
from mitre-attack-agent-skills17
Defensive analysis aid for MITRE ATT&CK T1564.001 to help triage, detection engineering, hunting, and incident response around hidden files and directories.
This skill provides a structured, defense-focused analysis of the MITRE ATT&CK sub-technique T1564.001 (Hidden Files and Directories). It helps map observed behaviors to ATT&CK, produce detection ideas, prioritise telemetry collection, and generate repeatable artifacts such as detection briefs, hunt plans, and incident-response notes. The skill bundles machine-readable metadata and templates to make outputs consistent and actionable.
Use this skill during triage, detection engineering, threat hunting, ATT&CK coverage assessments, or when planning safe adversary-emulation exercises. It's appropriate when log evidence or analyst questions reference hidden files, suspicious dotfiles, UF_HIDDEN flags on macOS, or patterns suggesting directory/file hiding for stealth.
Best used by agents with code execution and file access (Claude Code, Copilot-style assistants, or other agents that can read bundled JSON/templates) so they can render templates and run the included helper scripts.
This skill has not been reviewed by our automated audit pipeline yet.
MITRE ATT&CK T1098 — Account Manipulation
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi
MITRE ATT&CK — T1569.001 Launchctl
Defensive analysis skill for MITRE ATT&CK T1569.001 (Launchctl): detection, triage, and mitigation guidance for macOS adversary activity.
MITRE ATT&CK T1557.001: Name Resolution Poisoning & SMB Relay
Defensive analysis skill for MITRE ATT&CK T1557.001: helps triage, detection engineering, hunting, and incident response for name-resolution poisoning and SMB r
ATT&CK T1560.003 — Archive via Custom Method
Defensive analysis skill for MITRE ATT&CK T1560.003: helps map observations, produce detection ideas, and create triage and mitigation briefs for custom archive