
from MITRE ATT&CK Agent Skills24
Analyzes the T1583.006 sub-technique (Web Services) for triage, detection engineering, and incident response mapping.
This skill enables an agent to provide deep defensive analysis of the MITRE ATT&CK sub-technique T1583.006 (Web Services). It assists in understanding how adversaries register for web services to hide their operations during targeting, C2, exfiltration, or phishing.
Use this skill when tasks involve TTP mapping, detection engineering, threat hunting, or authorized adversary emulation planning specifically related to the use of web services as a resource for targeting.
render_brief.py to generate Markdown defensive briefs.Designed for AI agents capable of executing local scripts and reading structured reference files (e.g., Claude Code, Codex).
This skill has not been reviewed by our automated audit pipeline yet.
MITRE ATT&CK T1098 — Account Manipulation
Defensive analysis and guidance for MITRE ATT&CK technique T1098 (Account Manipulation): detection, triage, hunting, and mitigation planning for enterprise envi
MITRE ATT&CK — T1569.001 Launchctl
Defensive analysis skill for MITRE ATT&CK T1569.001 (Launchctl): detection, triage, and mitigation guidance for macOS adversary activity.
MITRE ATT&CK T1557.001: Name Resolution Poisoning & SMB Relay
Defensive analysis skill for MITRE ATT&CK T1557.001: helps triage, detection engineering, hunting, and incident response for name-resolution poisoning and SMB r
ATT&CK T1560.003 — Archive via Custom Method
Defensive analysis skill for MITRE ATT&CK T1560.003: helps map observations, produce detection ideas, and create triage and mitigation briefs for custom archive
MITRE ATT&CK — Hidden Files & Directories (T1564.001)
Defensive analysis aid for MITRE ATT&CK T1564.001 to help triage, detection engineering, hunting, and incident response around hidden files and directories.
MITRE ATT&CK T1633.001 — System Checks
Defensive analysis skill for MITRE ATT&CK T1633.001 (System Checks) — aids triage, detection engineering, hunting, and emulation planning for mobile platforms.
MITRE ATT&CK T1074: Data Staged
Analyze and detect the T1074 'Data Staged' technique in enterprise environments, supporting TTP triage and detection engineering.