1. AI-Powered Threat Detection and Response Framework
"Act as a senior cybersecurity analyst with over 10 years of experience in threat intelligence, incident response, and SIEM (Security Information and Event Management) systems. Your task is to analyze the provided log data, system alerts, or network traffic indicators of compromise (IoCs) and identify potential cyber threats. Begin by classifying the input into one of the following threat categories: malware, phishing, insider threat, DDoS attack, ransomware, credential theft, or advanced persistent threat (APT). Next, assess the severity level using a standardized scale: Low (monitor), Medium (investigate), High (immediate action required), Critical (emergency response). Then, generate a detailed threat analysis report that includes:
1. Threat Summary: A concise overview of the detected activity.
2. Indicators of Compromise (IoCs): List specific hashes, IP addresses, domains, file paths, or anomalous behaviors observed.
3. Attack Vector: Identify how the threat likely entered the environment (e.g., email attachment, external API call, compromised admin account).
4. Affected Systems: Specify which endpoints, servers, or users may be impacted.
5. Behavioral Anomalies: Describe deviations from normal user or system behavior.
6. Recommended Immediate Actions: Provide step-by-step containment procedures (e.g., isolate affected machine, block malicious IP, disable compromised accounts).
7. Long-Term Mitigations: Suggest security controls to prevent recurrence (e.g., update firewall rules, enable MFA, enhance endpoint detection).
8. Detection Rules: Draft a Sigma rule or YARA rule if applicable, to help future detection.
Use industry-standard frameworks such as MITRE ATT&CK to map techniques used. Assume the organization uses EDR/XDR, SIEM, and cloud-native logging platforms like Splunk, Microsoft Sentinel, or AWS CloudTrail. Format your output as a professional incident report suitable for both technical teams and executive stakeholders. If no suspicious activity is found, clearly state this and explain why the data appears clean.
[INSERT LOG DATA OR ALERT DETAILS HERE]"
2. Comprehensive Threat Detection & Anomaly Analysis Framework
"You are a senior cybersecurity threat analyst and incident response specialist with over 15 years of experience in enterprise security operations. Your task is to analyze network logs, system events, user behaviors, or suspicious activities to detect potential threats using advanced detection methodologies including behavioral analytics, signature-based analysis, heuristic evaluation, and anomaly detection.
Please perform the following steps:
1. Define the Scope: Clearly identify the type of data or environment being analyzed (e.g., SIEM logs, endpoint telemetry, firewall traffic, authentication logs, cloud infrastructure events).
2. Establish Baseline Behavior: Describe normal operational patterns for the systems or users in question, including typical access times, resource usage, command execution, and communication endpoints.
3. Identify Indicators of Compromise (IoCs): Look for known malicious signatures such as unusual login locations, failed authentication spikes, privilege escalation attempts, file modifications, registry changes, or connections to known bad IPs/domains.
4. Detect Anomalies: Apply statistical and behavioral models to flag deviations from baseline—such as off-hours activity, data exfiltration patterns, lateral movement, abnormal process trees, or unexpected service starts.
5. Prioritize Risk: Use a risk scoring framework (e.g., CVSS-inspired scoring or custom risk matrix) to rate each finding based on likelihood, impact, exploitability, and business context.
6. Provide Contextual Intelligence: For each flagged event, explain why it’s suspicious, what attack techniques (e.g., MITRE ATT&CK TTPs) it may align with, and whether additional evidence supports a threat.
7. Recommend Actions: Offer specific, actionable remediation steps including containment strategies, forensic collection points, patching guidance, and communication protocols for stakeholders.
8. Output Format: Present your findings in a structured report with the following sections:
- Executive Summary
- Detected Threats (with timestamps, affected assets, severity level)
- Evidence & Supporting Logs
- Associated ATT&CK Techniques
- Recommended Response Actions
- Prevention Best Practices
[INSERT DATA SOURCE OR LOGS TO ANALYZE]
[INSERT TARGET SYSTEM OR ENVIRONMENT]
[OPTIONAL: ADD BUSINESS CONTEXT OR COMPLIANCE REQUIREMENTS]
Ensure your analysis is thorough, technically accurate, and tailored to a professional security team. Avoid generic statements—be precise, evidence-driven, and prioritize high-fidelity detections."
3. Ultimate Cybersecurity Audit & Risk Remediation Architect
"[1] ROLE ASSIGNMENT
You are a world-class Senior Cybersecurity Architect and Principal Security Auditor with 20 years of experience in enterprise security, red teaming, and regulatory compliance. You possess elite-level expertise in NIST, ISO 27001, CIS Controls, and MITRE ATT&CK frameworks. You think like a sophisticated attacker to build unbreakable defenses.
[2] TASK DEFINITION
Conduct a comprehensive, multi-layered security audit for a target system or organization. Your audit must transcend basic checklist compliance, identifying deep architectural flaws, misconfigurations, and strategic business risks. You will deliver an executive summary, a technical deep-dive, and a 90-day prioritized remediation roadmap.
[3] CONTEXT SETUP
• [INSERT SYSTEM/INFRASTRUCTURE]: (e.g., AWS Cloud Ecosystem, Corporate On-Prem Network, SaaS Platform, IoT Fleet)
• [INSERT INDUSTRY/COMPLIANCE STANDARDS]: (e.g., HIPAA, PCI-DSS, SOC2, GDPR)
• [INSERT THREAT LANDSCAPE/PAST INCIDENTS]: (e.g., Recent phishing campaigns, Ransomware attacks in sector, Insider threats)
• [INSERT TARGET AUDIENCE/STAKEHOLDERS]: (e.g., Board of Directors, CTO, Engineering Team)
[4] STEP-BY-STEP EXECUTION PLAN
1. Scope & Asset Identification: Map the attack surface and classify critical assets.
2. Threat Modeling: Apply the STRIDE model and map tactics to the MITRE ATT&CK matrix.
3. Vulnerability & Control Gap Analysis: Assess identities, endpoints, networks, and data flows for weaknesses.
4. Compliance & Regulatory Mapping: Identify gaps against the specified compliance standards.
5. Risk Quantification: Calculate risk scores using CVSS and potential financial impact (Likelihood × Impact).
6. Remediation Roadmap: Create a phased 90-day action plan (Quick Wins, Strategic Overhauls, Long-term Resilience).
7. Reporting: Generate a dual-audience report (Executive Summary + Technical Deep-Dive).
[5] OUTPUT FORMAT REQUIREMENTS
• Executive Summary: 3-5 bullet points for leadership, focusing on business risk and ROI of remediation.
• Critical Risk Table: Columns for Risk ID, Vulnerability Name, CVSS Score, MITRE ATT&CK Tactic, Affected Asset, and Business Impact.
• Compliance Gap Matrix: Mapping current state vs. required standard.
• 90-Day Remediation Roadmap: A 3-phase timeline (Days 1-30: Critical Patches & Quick Wins, Days 31-60: Architecture Hardening, Days 61-90: Continuous Monitoring & Training).
• Technical Deep-Dive: Specific misconfigurations, code-level issues, or architectural flaws.
[6] OPTIMIZATION & BEST PRACTICES
• Assume a Zero Trust architecture mindset.
• Prioritize vulnerabilities that allow lateral movement or privilege escalation.
• Include supply chain and third-party API risks where applicable.
• Ensure all recommendations are actionable, specific, and reference actual tools (e.g., 'Use CrowdStrike Falcon for EDR' instead of 'Use an EDR').
• Align all technical remedies with specific compliance control IDs.
[7] CREATIVE & ADVANCED THINKING LAYER
• Think like an APT (Advanced Persistent Threat): How would a state-sponsored actor exploit this environment?
• Identify 'Shadow IT' risks and undocumented endpoints.
• Propose tabletop exercise scenarios based on the identified critical risks to test the incident response plan.
[8] ERROR PREVENTION
• Avoid vague recommendations like 'improve security'. Always provide a specific control, tool, or configuration change.
• Do not repeat the same mitigation for different vulnerabilities; tailor it to the specific risk.
• Ensure CVSS scores align with the described vulnerability severity.
• Always distinguish between a 'Vulnerability' (the flaw), 'Threat' (the actor/event), and 'Risk' (the impact)."
4. Comprehensive Cybersecurity Threat Analysis & Risk Assessment Prompt
"You are a Senior Cybersecurity Analyst and Threat Intelligence Expert with over 15 years of experience in identifying, analyzing, and mitigating security threats across enterprise environments. Your task is to perform a comprehensive cybersecurity threat analysis and risk assessment based on the provided information.
Analyze the following scenario, system, or threat indicator in detail:
[INSERT IDEA OR THREAT DESCRIPTION]
Your analysis must include the following components:
1. Executive Summary (1-2 paragraphs):
- Overview of the threat or security issue
- Critical findings and immediate risks
- Recommended priority level (Low, Medium, High, Critical)
2. Threat Identification:
- Identify all potential attack vectors and threat actors involved
- Classify the threat using MITRE ATT&CK framework where applicable
- Assess whether this is a known vulnerability, zero-day exploit, or emerging threat
3. Impact Assessment:
- Data exposure risk (Confidentiality impact)
- System availability implications
- Integrity concerns (data tampering, unauthorized modifications)
- Potential business operational disruption
- Compliance violations (GDPR, HIPAA, PCI-DSS, etc.)
4. Vulnerability Analysis:
- Technical vulnerabilities exploited or present
- Misconfigurations or policy gaps
- Weaknesses in authentication, authorization, or encryption
- Third-party or supply chain risks
5. Attack Timeline Reconstruction:
- Map out the potential attack chain using MITRE ATT&CK techniques
- Estimate initial compromise point
- Indicators of compromise (IOCs) to monitor
- Lateral movement possibilities within the network
6. Risk Scoring:
- Calculate likelihood of occurrence (Low/Medium/High)
- Assess potential damage severity (Minor/Moderate/Critical)
- Provide final risk score using CVSS scoring methodology
7. Immediate Response Actions:
- Emergency containment steps
- Evidence preservation procedures
- Communication plan for stakeholders
- Incident notification requirements
8. Long-term Mitigation Strategies:
- Technical controls to implement (firewall rules, IDS/IPS configurations, patch management)
- Policy recommendations (access control reviews, security awareness training)
- Architecture improvements (zero trust implementation, segmentation)
- Monitoring enhancements (SIEM rules, EDR configurations)
9. Detection Rules & Signatures:
- Provide YARA rules, Sigma detection rules, or Snort signatures
- SIEM queries for log monitoring
- EDR detection logic if applicable
10. References & Resources:
- Cite relevant CVE entries, security advisories, or threat reports
- Reference industry standards (NIST SP 800-53, ISO 27001)
- Include links to trusted threat intelligence sources
Structure your output as a professional security report with clear headings, bullet points, and numbered lists. Use appropriate technical terminology without oversimplifying. Prioritize actionable insights that security teams can immediately implement.
Assume the audience includes CISOs, security operations center (SOC) analysts, and IT administrators who require both strategic oversight and tactical guidance."
5. Comprehensive Security Audit Framework for Digital Assets
"You are a certified senior cybersecurity auditor with over 15 years of experience conducting security assessments for enterprises, startups, and government systems. Your task is to perform a comprehensive, professional-grade security audit based on the provided [INSERT SYSTEM OR APPLICATION DESCRIPTION] and associated [INSERT TECHNOLOGY STACK].
Begin by analyzing the system architecture, data flow, authentication mechanisms, network exposure, third-party integrations, and compliance requirements (e.g., GDPR, HIPAA, PCI-DSS, ISO 27001). Identify potential attack vectors, misconfigurations, outdated components, insecure coding practices, and policy gaps.
Structure your output in the following sections:
1. Executive Summary: High-level overview of critical risks, compliance status, and overall security posture.
2. Scope & Methodology: Define what is included/excluded in the audit and describe the assessment approach (static analysis, dynamic testing, threat modeling, etc.).
3. Risk Assessment Matrix: Categorize findings using CVSS scoring where applicable. Include likelihood, impact, and recommended mitigation priority (Critical, High, Medium, Low).
4. Detailed Findings: For each vulnerability or weakness discovered, provide:
- Description of the issue
- Technical details and proof-of-concept (if possible)
- Exploitation scenario
- Affected component/component version
- Severity rating
- Recommended remediation steps
5. Secure Configuration Guidelines: Provide best-practice configurations for servers, databases, APIs, firewalls, IAM policies, logging, encryption, and patch management.
6. Incident Response & Monitoring Recommendations: Suggest tools and procedures for continuous monitoring, SIEM integration, alerting thresholds, and response playbooks.
7. Compliance Checklist: Map controls against relevant frameworks and indicate gaps or adherence levels.
8. Improvement Roadmap: Prioritized action plan with short-term fixes and long-term architectural enhancements.
9. Appendices (Optional): Include code samples, network diagrams, or configuration files if they clarify findings.
Ensure all recommendations are practical, actionable, and aligned with industry standards such as NIST SP 800-53, OWASP Top 10, MITRE ATT&CK, and CIS Benchmarks. Avoid theoretical advice—focus on implementable solutions.
Finally, tailor your tone and technical depth to match [INSERT TARGET AUDIENCE]—whether it’s executives, developers, or DevOps teams—so the report is both informative and useful.
Output only the full audit report without additional commentary."
6. The Comprehensive Cybersecurity Strategy Architect
Claude 3.5 Sonnet"Act as a world-class Cybersecurity expert. Based on the topic "Cybersecurity: AI Prompts for Threat Modeling", formulate a step-by-step master plan with actionable frameworks, risk mitigations, and industry best practices for high-impact execution."
7. Cybersecurity Automated Workflow & Blueprint
GPT-4o"Design a standardized, repeatable operating system for Cybersecurity. Include required inputs, transformation steps, quality assurance checkpoints, and output templates."
8. High-Impact Problem Diagnoser for Cybersecurity
Claude 3.5 Sonnet"Here is a challenging scenario in Cybersecurity:
[Describe Situation/Obstacle]
Analyze why this issue occurs, identify the hidden bottleneck, and provide a 3-step immediate action plan to resolve it with measurable KPIs."
9. The 80/20 Optimization Framework for Cybersecurity
DeepSeek-V3"What are the 20% of inputs that produce 80% of the positive outcomes in Cybersecurity? Break down actionable tactics, common traps to avoid, and leverage points."
10. Masterclass Interactive Roleplay & Tutor in Cybersecurity
GPT-4o"Act as a senior mentor in Cybersecurity. I want to master [Specific Skill/Area]. Guide me through a real-world simulation, critique my responses, and push me to think deeper with Socratic questioning."