
from MITRE ATT&CK Agent Skills24
Defensive analysis skill for MITRE ATT&CK T1633.001 (System Checks) — aids triage, detection engineering, hunting, and emulation planning for mobile platforms.
This skill provides structured, defensive guidance for the MITRE ATT&CK sub-technique T1633.001 (System Checks) in the mobile matrix. It helps analysts map observed behaviors to ATT&CK, prioritize telemetry, produce detection logic, and plan safe emulation or validation in controlled environments.
Use when you need to: triage mobile telemetry for defense-evasion behaviors, design detections for environment or virtualization checks, plan threat-hunting or incident-response playbooks related to system checks, or create controlled adversary-emulation scenarios. Ideal for Android/iOS investigations or detection engineering tasks.
Best used by agents with access to knowledge and document rendering tools (code-capable assistants that can run Python helpers), detection-engineering workflows, and those that can present structured Markdown outputs (e.g., Claude Code, copilot-style agents, or custom automation that can run the included scripts).
Defensive analysis skill for MITRE ATT&CK T1633.001 (System Checks on mobile). SKILL.md is well-structured with clear triggers, context, and output patterns. The bundled render_brief.py script is clean but fails at runtime because it depends on references/technique-profile.json which is not included in the scripts/ directory — only scripts are downloaded, not the references/ folder. No security concerns; purely informational defensive content.
One of many MITRE ATT&CK technique-specific skills. Well-organized but the script can't run standalone without the references directory. Purely defensive/informational — no offensive capability.
MITRE ATT&CK T1098 — Account Manipulation
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi
MITRE ATT&CK — T1569.001 Launchctl
Defensive analysis skill for MITRE ATT&CK T1569.001 (Launchctl): detection, triage, and mitigation guidance for macOS adversary activity.
MITRE ATT&CK T1557.001: Name Resolution Poisoning & SMB Relay
Defensive analysis skill for MITRE ATT&CK T1557.001: helps triage, detection engineering, hunting, and incident response for name-resolution poisoning and SMB r
ATT&CK T1560.003 — Archive via Custom Method
Defensive analysis skill for MITRE ATT&CK T1560.003: helps map observations, produce detection ideas, and create triage and mitigation briefs for custom archive
MITRE ATT&CK — Hidden Files & Directories (T1564.001)
Defensive analysis aid for MITRE ATT&CK T1564.001 to help triage, detection engineering, hunting, and incident response around hidden files and directories.
MITRE ATT&CK T1074: Data Staged
Analyze and detect the T1074 'Data Staged' technique in enterprise environments, supporting TTP triage and detection engineering.
MITRE ATT&CK T1583.006: Web Services
Analyzes the T1583.006 sub-technique (Web Services) for triage, detection engineering, and incident response mapping.