
from mitre-attack-agent-skills18
Defensive analysis skill for MITRE ATT&CK T1633.001 (System Checks) — aids triage, detection engineering, hunting, and emulation planning for mobile platforms.
This skill provides structured, defensive guidance for the MITRE ATT&CK sub-technique T1633.001 (System Checks) in the mobile matrix. It helps analysts map observed behaviors to ATT&CK, prioritize telemetry, produce detection logic, and plan safe emulation or validation in controlled environments.
Use when you need to: triage mobile telemetry for defense-evasion behaviors, design detections for environment or virtualization checks, plan threat-hunting or incident-response playbooks related to system checks, or create controlled adversary-emulation scenarios. Ideal for Android/iOS investigations or detection engineering tasks.
Best used by agents with access to knowledge and document rendering tools (code-capable assistants that can run Python helpers), detection-engineering workflows, and those that can present structured Markdown outputs (e.g., Claude Code, copilot-style agents, or custom automation that can run the included scripts).
This skill has not been reviewed by our automated audit pipeline yet.
MITRE ATT&CK T1098 — Account Manipulation
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi
MITRE ATT&CK — T1569.001 Launchctl
Defensive analysis skill for MITRE ATT&CK T1569.001 (Launchctl): detection, triage, and mitigation guidance for macOS adversary activity.
MITRE ATT&CK T1557.001: Name Resolution Poisoning & SMB Relay
Defensive analysis skill for MITRE ATT&CK T1557.001: helps triage, detection engineering, hunting, and incident response for name-resolution poisoning and SMB r
ATT&CK T1560.003 — Archive via Custom Method
Defensive analysis skill for MITRE ATT&CK T1560.003: helps map observations, produce detection ideas, and create triage and mitigation briefs for custom archive
MITRE ATT&CK — Hidden Files & Directories (T1564.001)
Defensive analysis aid for MITRE ATT&CK T1564.001 to help triage, detection engineering, hunting, and incident response around hidden files and directories.