Product & Planning
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
-
santosomar Bundle Attack Mob T1422 002 Wi Fi DiscoveryAnalyze MITRE ATT&CK T1422.002 Wi-Fi Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.002, Wi-Fi Discovery, or mobile ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
-
santosomar Bundle Attack Ics T0846 002 Broadcast DiscoveryAnalyze MITRE ATT&CK T0846.002 Broadcast Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846.002, Broadcast Discovery, or ics ATT&CK. Adversaries may perform broadcast discovery requests to enumerate systems and devices on a network.
-
santosomar Bundle Attack Ics T0846 003 Multicast DiscoveryAnalyze MITRE ATT&CK T0846.003 Multicast Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846.003, Multicast Discovery, or ics ATT&CK. Adversaries may perform multicast discovery requests which is when one system or device sends messages to all systems and devices in a pre-defined group on a network (or subnet) and then waits for a response.
-
santosomar Bundle Attack Ics T0846 Remote System DiscoveryAnalyze MITRE ATT&CK T0846 Remote System Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846, Remote System Discovery, or ics ATT&CK. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
-
santosomar Bundle Attack Ent T1087 Account DiscoveryAnalyze MITRE ATT&CK T1087 Account Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087, Account Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
-
santosomar Bundle Attack Ent T1057 Process DiscoveryAnalyze MITRE ATT&CK T1057 Process Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1057, Process Discovery, or enterprise ATT&CK. Adversaries may attempt to get information about running processes on a system.
-
santosomar Bundle Attack Ent T1518 Software DiscoveryAnalyze MITRE ATT&CK T1518 Software Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1518, Software Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
-
santosomar Bundle Attack Ent T1016 002 Wi Fi DiscoveryAnalyze MITRE ATT&CK T1016.002 Wi-Fi Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016.002, Wi-Fi Discovery, or enterprise ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
-
santosomar Bundle Attack Ent T1482 Domain Trust DiscoveryAnalyze MITRE ATT&CK T1482 Domain Trust Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1482, Domain Trust Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
santosomar Bundle Attack Ent T1124 System Time DiscoveryAnalyze MITRE ATT&CK T1124 System Time Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1124, System Time Discovery, or enterprise ATT&CK. An adversary may gather the system time and/or time zone settings from a local or remote system.
-
santosomar Bundle Attack Ent T1615 Group Policy DiscoveryAnalyze MITRE ATT&CK T1615 Group Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1615, Group Policy Discovery, or enterprise ATT&CK. Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or us…
-
santosomar Bundle Attack Ent T1018 Remote System DiscoveryAnalyze MITRE ATT&CK T1018 Remote System Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1018, Remote System Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
santosomar Bundle Attack Ent T1652 Device Driver DiscoveryAnalyze MITRE ATT&CK T1652 Device Driver Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1652, Device Driver Discovery, or enterprise ATT&CK. Adversaries may attempt to enumerate local device drivers on a victim host.
-
santosomar Bundle Attack Ent T1680 Local Storage DiscoveryAnalyze MITRE ATT&CK T1680 Local Storage Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1680, Local Storage Discovery, or enterprise ATT&CK. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
santosomar Bundle Attack Ent T1135 Network Share DiscoveryAnalyze MITRE ATT&CK T1135 Network Share Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1135, Network Share Discovery, or enterprise ATT&CK. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Mov…
-
santosomar Bundle Attack Ent T1007 System Service DiscoveryAnalyze MITRE ATT&CK T1007 System Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1007, System Service Discovery, or enterprise ATT&CK. Adversaries may try to gather information about registered local system services.
-
santosomar Bundle Attack Ent T1526 Cloud Service DiscoveryAnalyze MITRE ATT&CK T1526 Cloud Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1526, Cloud Service Discovery, or enterprise ATT&CK. An adversary may attempt to enumerate the cloud services running on a system after gaining access.
-
santosomar Bundle Attack Ent T1046 Network Service DiscoveryAnalyze MITRE ATT&CK T1046 Network Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1046, Network Service Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
santosomar Bundle Attack Ent T1201 Password Policy DiscoveryAnalyze MITRE ATT&CK T1201 Password Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1201, Password Policy Discovery, or enterprise ATT&CK. Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
-
santosomar Bundle Attack Ent T1033 System Owner User DiscoveryAnalyze MITRE ATT&CK T1033 System Owner/User Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1033, System Owner/User Discovery, or enterprise ATT&CK. Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
santosomar Bundle Attack Ent T1069 Permission Groups DiscoveryAnalyze MITRE ATT&CK T1069 Permission Groups Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069, Permission Groups Discovery, or enterprise ATT&CK. Adversaries may attempt to discover group and permission settings.
-
santosomar Bundle Attack Ent T1120 Peripheral Device DiscoveryAnalyze MITRE ATT&CK T1120 Peripheral Device Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1120, Peripheral Device Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.(Citation: Peripheral Discovery Linux)(Citation: Peripheral Discovery macOS) Peripheral devic…
-
santosomar Bundle Attack Mob T1420 File And Directory DiscoveryAnalyze MITRE ATT&CK T1420 File and Directory Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1420, File and Directory Discovery, or mobile ATT&CK. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.
-
santosomar Bundle Attack Mob T1426 System Information DiscoveryAnalyze MITRE ATT&CK T1426 System Information Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1426, System Information Discovery, or mobile ATT&CK. Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.
-
santosomar Bundle Attack Mob T1418 001 Security Software DiscoveryAnalyze MITRE ATT&CK T1418.001 Security Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418.001, Security Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.
-
santosomar Bundle Attack Ent T1010 Application Window DiscoveryAnalyze MITRE ATT&CK T1010 Application Window Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1010, Application Window Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of open application windows.
-
santosomar Bundle Attack Ent T1082 System Information DiscoveryAnalyze MITRE ATT&CK T1082 System Information Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1082, System Information Discovery, or enterprise ATT&CK. An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
santosomar Bundle Attack Ent T1614 System Location DiscoveryAnalyze MITRE ATT&CK T1614 System Location Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1614, System Location Discovery, or enterprise ATT&CK. Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
-
santosomar Bundle Attack Ent T1614 001 System Language DiscoveryAnalyze MITRE ATT&CK T1614.001 System Language Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1614.001, System Language Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
santosomar Bundle Attack Mob T1422 001 Internet Connection DiscoveryAnalyze MITRE ATT&CK T1422.001 Internet Connection Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.001, Internet Connection Discovery, or mobile ATT&CK. Adversaries may check for Internet connectivity on compromised systems.
-
santosomar Bundle Attack Ent T1083 File And Directory DiscoveryAnalyze MITRE ATT&CK T1083 File and Directory Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1083, File and Directory Discovery, or enterprise ATT&CK. Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
santosomar Bundle Attack Ent T1580 Cloud Infrastructure DiscoveryAnalyze MITRE ATT&CK T1580 Cloud Infrastructure Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1580, Cloud Infrastructure Discovery, or enterprise ATT&CK. An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
-
santosomar Bundle Attack Ent T1217 Browser Information DiscoveryAnalyze MITRE ATT&CK T1217 Browser Information Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1217, Browser Information Discovery, or enterprise ATT&CK. Adversaries may enumerate information about browsers to learn more about compromised environments.
-
santosomar Bundle Attack Ent T1518 001 Security Software DiscoveryAnalyze MITRE ATT&CK T1518.001 Security Software Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1518.001, Security Software Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
santosomar Bundle Attack Ent T1016 001 Internet Connection DiscoveryAnalyze MITRE ATT&CK T1016.001 Internet Connection Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016.001, Internet Connection Discovery, or enterprise ATT&CK. Adversaries may check for Internet connectivity on compromised systems.
-
frnyb Skill Create BacklogCreate or update a detailed implementation backlog for a feature through a code-informed interview, then decompose the agreed design into atomic tasks. Use when the user wants to plan a feature, write a backlog, create implementation tasks, or prepare work before coding.
Frequently asked questions
What are Product & Planning agent skills?
Product & planning agent skills structure the thinking side of building: specs, PRDs, user stories, roadmaps, and prioritization frameworks. Install one and your AI agent produces planning documents with the same rigor and format every time.
Which Product & Planning skills are most installed?
Popular Product & Planning skills on SkillMD right now include attack-mob-t1422-002-wi-fi-discovery, attack-ics-t0846-002-broadcast-discovery, attack-ics-t0846-003-multicast-discovery. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Product & Planning skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.