
from mitre-attack-agent-skills16
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi
Provides a defensive-focused skill that analyzes MITRE ATT&CK technique T1098 (Account Manipulation). It helps the agent map evidence to the ATT&CK technique, produce detection hypotheses, create triage and hunt plans, and generate mitigation and containment recommendations. The skill bundles structured metadata, templates, and rendering scripts to produce concise defensive briefs.
Use this skill when investigating account manipulation behaviors, planning detection logic for account-related TTPs, drafting threat-hunting playbooks, conducting incident-response mapping, or preparing controlled adversary-emulation exercises. It's intended for defensive analysts and detection engineers seeking ATT&CK-mapped outputs.
scripts/render_brief.py (render detection briefs)references/technique-profile.json, references/detection-and-mitigation.md, references/known-threat-context.mdBest used by agents that can run local scripts and produce structured text outputs (automation-capable assistants used for security analysis, e.g., code-capable agents and automation runners).
This skill has not been reviewed by our automated audit pipeline yet.