Threat Intelligence Report Builder

Write a structured threat report - summary, TTPs, indicators, confidence, timeline, ATT&CK mappings, mitigations - and export it as Markdown, HTML or JSON.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

Nothing you type leaves this page. The report is assembled in your browser and is not saved anywhere. Export it, or export the JSON to continue later.

1. Identity

2. Executive section

3. Technical section

4. Review and export

Exports unlock after a sensitive-information review of the current content. The indicator table is excluded from the review because it holds network indicators on purpose. Any edit after the review locks the exports again.

Preview

Two audiences, one document

A threat report is read by two different people. A manager needs to know in two minutes what happened, how sure you are, and what to decide. An analyst needs the indicators, the techniques, the timeline and the evidence behind each judgement. This builder keeps the two sections apart: the executive summary and key judgements come first, and the technical material follows. Neither has to wade through the other's content.

State your confidence, and why

Every key judgement carries its own confidence level. The report also asks for sources graded on the Admiralty (NATO) system: source reliability from A to F, information credibility from 1 to 6. A judgement drawn from a single unconfirmed source reads very differently from one corroborated three times, and the reader can only tell the difference if you say so. The limitations section is not optional in good intelligence writing. Say what you could not see.

Indicators are checked before they are published

Every indicator line goes through the same typing and normalisation as the IOC Normalizer. Invalid and ambiguous values are flagged before they reach the report, not after a partner's blocklist rejects them. Exported indicators are defanged by default (hxxps://evil[.]example), so an HTML or Markdown copy cannot turn into a clickable link to live attacker infrastructure. ATT&CK technique IDs are checked for the correct format.

The review before export

Incident-derived reports leak. A pasted log line carries a bearer token, a timeline mentions a colleague's email address, and an asset list includes an internal hostname. Before any export, the whole report is scanned for credentials, personal data and internal network names. Each hit is shown (masked) with where it was found. You can redact everything consistently in one step, or confirm you have read the list. Pattern matching cannot find a name written in prose, so read the result.

Deterministic, not generated

The builder never writes content for you and never sends your report to an AI service. Every sentence in the export is one you wrote. The HTML export is self-contained and escapes every value. It also carries a content security policy that blocks scripts, so attacker-supplied strings quoted in the report cannot run in a reader's browser.

Frequently asked questions

Is my report saved?

No. Nothing is stored in the browser or sent to a server. Export the JSON if you want to continue later, then open it with "Open a saved report".

How do I produce a PDF?

Use "Print / save as PDF" and choose Save as PDF in the print dialog. The print layout omits the site's navigation and keeps table rows together.

Which TLP version does this use?

TLP 2.0 labels, including CLEAR and AMBER+STRICT. The label is printed at the top of every export.

Can it map techniques for me?

No, and it does not guess. Enter the technique IDs you have evidence for. The MITRE ATT&CK Mapper can help you find candidates, which you then review.

References

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.