ResearchCritical riskConsensus useful

AI Playbook for Threat Intelligence Fusion & Indicator Prioritization

Your threat intel team has received three separate feeds — ISACs, a commercial TIP, and a classified government advisory — with overlapping but inconsistent IOCs targeting critical infrastructure in the energy sector. Forty-seven IOCs are in conflict: some appear on one list as confirmed malicious and on another as benign infrastructure. You have 6 hours before the next executive threat brief.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: Your threat intel team has received three separate feeds — ISACs, a commercial TIP, and a classified government advisory — with overlapping but inconsistent IOCs targeting critical infrastructure in the energy sector.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Threat Intelligence Fusion & Indicator Prioritization".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • ISAC threat feed (STIX 2.1 format) - Commercial TIP export (CSV) - Government advisory IOC list - Your organization's current blocklist and allow list

Attachments: Spreadsheets (Spreadsheets)

The Prompt

You are a senior threat intelligence analyst preparing a fused, de-conflicted IOC briefing for critical infrastructure operators.  I am attaching: - ISAC threat feed (STIX 2.1 format) - Commercial TIP export (CSV) - Government advisory IOC list - Your organization's current blocklist and allow list

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. De-conflict all 47 overlapping IOCs — identify each conflict, assess the source credibility weighting for each feed, and produce a final verdict (confirmed malicious, false positive, or requires further analysis) for each disputed indicator.
2. Prioritize all confirmed IOCs by threat severity, infrastructure targeting pattern, and recency — producing a tiered action list for immediate blocking, monitoring, and watchlist.
3. Identify any IOCs that appear on your current allow list and assess whether the allow list entry was legitimate or represents a potential compromise of your baseline.
4. Synthesize the three feeds into a unified threat narrative — identify the likely campaign, targeting pattern, and operational tempo.
5. Produce an executive brief and a technical indicator package suitable for distribution to sector peers.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Multi-model consensus de-confliction verdict per IOC
  • Tiered action list with blocking priority scores
  • Allow list conflict register with compromise risk flags
  • Unified campaign narrative with model-agreement score
  • Executive brief and distributable indicator package

Review before you act

  • Validate this output against source files before relying on it: De-conflict all 47 overlapping IOCs — identify each conflict, assess the source credibility weighting for each feed, and produce a final verdict (confirmed malicious, false positive, or requires further analysis) for each disputed indicator.
  • Validate this output against source files before relying on it: Prioritize all confirmed IOCs by threat severity, infrastructure targeting pattern, and recency — producing a tiered action list for immediate blocking, monitoring, and watchlist.
  • Validate this output against source files before relying on it: Identify any IOCs that appear on your current allow list and assess whether the allow list entry was legitimate or represents a potential compromise of your baseline.
  • Validate this output against source files before relying on it: Synthesize the three feeds into a unified threat narrative — identify the likely campaign, targeting pattern, and operational tempo.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Threat Intelligence Fusion & Indicator Prioritization, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus de-confliction verdict per ioc; tiered action list with blocking priority scores; allow list conflict register with compromise risk flags; unified campaign narrative with model-agreement score. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.

US FederalCybersecurity Threat IntelResearchCriticalSpreadsheets

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.