Research & Search
Research agent skills teach AI agents to gather and synthesize information properly: literature reviews, competitive analysis, web research with citations, and structured summaries. Each SKILL.md encodes a method, not just a prompt, so results stay consistent across runs.
-
santosomar Bundle Attack Ent T1127 002 ClickonceAnalyze MITRE ATT&CK T1127.002 ClickOnce in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1127.002, ClickOnce, or enterprise ATT&CK. Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility.(Citation: Burke/CISA ClickOnce BlackHat) ClickOnce is a deployment that enable…
-
santosomar Bundle Attack Ent T1606 002 Saml TokensAnalyze MITRE ATT&CK T1606.002 SAML Tokens in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1606.002, SAML Tokens, or enterprise ATT&CK. An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.(Citation: Microsoft SolarWinds Steps) The default lifetime of a SAML token is one hour…
-
santosomar Bundle Attack Ent T1136 Create AccountAnalyze MITRE ATT&CK T1136 Create Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136, Create Account, or enterprise ATT&CK. Adversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access, creating such accounts may be used to establish secondary credentiale…
-
santosomar Bundle Attack Ent T1564 007 Vba StompingAnalyze MITRE ATT&CK T1564.007 VBA Stomping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.007, VBA Stomping, or enterprise ATT&CK. Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.(Citation: FireEye VBA stomp Feb 2020) MS Office document…
-
santosomar Bundle Attack Ent T1027 017 Svg SmugglingAnalyze MITRE ATT&CK T1027.017 SVG Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.017, SVG Smuggling, or enterprise ATT&CK. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.(Citation: Trustwave SVG Smuggling 2025) SVGs, or Scalable Vector Graphics, are vector-based…
-
santosomar Bundle Attack Ent T1176 002 Ide ExtensionsAnalyze MITRE ATT&CK T1176.002 IDE Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176.002, IDE Extensions, or enterprise ATT&CK. Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.(Citation: Mnemonic misuse visual studio) IDEs such as Visual Studio Code, IntelliJ IDEA, and…
-
santosomar Bundle Attack Ent T1558 001 Golden TicketAnalyze MITRE ATT&CK T1558.001 Golden Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.001, Golden Ticket, or enterprise ATT&CK. Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.(Citation: AdSecurity Kerberos GT Aug 2015) Golden tickets enable adversaries to gene…
-
santosomar Bundle Attack Ent T1565 Data ManipulationAnalyze MITRE ATT&CK T1565 Data Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1565, Data Manipulation, or enterprise ATT&CK. Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data.(Citation: Sygnia Elephant Beetle Jan 2022) By manipulating data, a…
-
santosomar Bundle Attack Ent T1600 Weaken EncryptionAnalyze MITRE ATT&CK T1600 Weaken Encryption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1600, Weaken Encryption, or enterprise ATT&CK. Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.(Citation: Cisco Synful Knock Evolution) Encryption can be used to prote…
-
santosomar Bundle Attack Ent T1558 004 As Rep RoastingAnalyze MITRE ATT&CK T1558.004 AS-REP Roasting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.004, AS-REP Roasting, or enterprise ATT&CK. Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by [Password Cracking](https://attack.mitre.org/techniques/T1110/002) Kerberos messages.(Citation: Harmj0y Roasting AS-REPs Ja…
-
santosomar Bundle Attack Ent T1684 002 Email SpoofingAnalyze MITRE ATT&CK T1684.002 Email Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684.002, Email Spoofing, or enterprise ATT&CK. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.(Citation: Proofpoint TA427 April 2024) In addition t…
-
santosomar Bundle Attack Ent T1078 002 Domain AccountsAnalyze MITRE ATT&CK T1078.002 Domain Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.002, Domain Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.(Citation: TechNet Credential Theft) Domain accounts are those…
-
santosomar Bundle Attack Ent T1601 001 Patch System ImageAnalyze MITRE ATT&CK T1601.001 Patch System Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1601.001, Patch System Image, or enterprise ATT&CK. Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.(Citation: Killing the myth of Cisco IOS rootkits) (Citation: Killing IOS diversity myth) (Citati…
-
santosomar Bundle Attack Ent T1555 005 Password ManagersAnalyze MITRE ATT&CK T1555.005 Password Managers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.005, Password Managers, or enterprise ATT&CK. Adversaries may acquire user credentials from third-party password managers.(Citation: ise Password Manager February 2019) Password managers are applications designed to store user credentials, normally in an encrypted…
-
santosomar Bundle Attack Ent T1574 013 KernelcallbacktableAnalyze MITRE ATT&CK T1574.013 KernelCallbackTable in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.013, KernelCallbackTable, or enterprise ATT&CK. Adversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run their own payloads.(Citation: Lazarus APT January 2022)(Citation: FinFisher exposed ) The <code>Kernel…
-
santosomar Bundle Attack Ent T1020 Automated ExfiltrationAnalyze MITRE ATT&CK T1020 Automated Exfiltration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1020, Automated Exfiltration, or enterprise ATT&CK. Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020) When automated exfiltration is used, othe…
-
santosomar Bundle Attack Ent T1222 001 Windows PermissionsAnalyze MITRE ATT&CK T1222.001 Windows Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222.001, Windows Permissions, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
-
santosomar Bundle Attack Ent T1490 Inhibit System RecoveryAnalyze MITRE ATT&CK T1490 Inhibit System Recovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1490, Inhibit System Recovery, or enterprise ATT&CK. Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.(Citation: Talos Olympic Destroyer 2018)(Citation: FireEye WannaCry 2017) Th…
-
santosomar Bundle Attack Ent T1222 002 Linux And Mac PermissionsAnalyze MITRE ATT&CK T1222.002 Linux and Mac Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222.002, Linux and Mac Permissions, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
-
santosomar Bundle Attack Ent T1003 005 Cached Domain CredentialsAnalyze MITRE ATT&CK T1003.005 Cached Domain Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.005, Cached Domain Credentials, or enterprise ATT&CK. Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.(Citation: Microsoft - Cached Creds) On Windows Vista and newer, the hash…
-
santosomar Bundle Attack Ent T1555 003 Credentials From Web BrowsersAnalyze MITRE ATT&CK T1555.003 Credentials from Web Browsers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.003, Credentials from Web Browsers, or enterprise ATT&CK. Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website usernames and passwor…
-
santosomar Bundle Attack Ent T1555 Credentials From Password StoresAnalyze MITRE ATT&CK T1555 Credentials from Password Stores in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555, Credentials from Password Stores, or enterprise ATT&CK. Adversaries may search for common password storage locations to obtain user credentials.(Citation: F-Secure The Dukes) Passwords are stored in several places on a system, depending on the operating system or application…
-
gmoriki Bundle Research Integrity AI Disclosure論文投稿時に生成 AI 利用を開示すべきか判断したい、学位論文における AI 使用の許容範囲を学生に伝えたい、 科研費申請で AI を使っていいか相談された、教員から「こういう使い方は OK か」と質問を受ける、 研究倫理セミナーで AI 使用の説明を求められる場面で使う研究支援職員向けスキル。 3 原則(補助ツール/二次的出典/独自視点再構築)と 3 場面別(投稿論文・学位論文・科研費)の 開示判断フローで、禁止事項 6 項目と日本学術振興会書式に合わせた開示テンプレを提供する。
-
santosomar Bundle Attack Ent T1222 File And Directory Permissions ModifAnalyze MITRE ATT&CK T1222 File and Directory Permissions Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222, File and Directory Permissions Modification, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
-
nicshik Skill Perplexity SearchSearch only mode for low-cost Perplexity lookup. Use when the user needs links, sources, snippets, or quick web lookup without answer synthesis or deep research.
-
santosomar Bundle Attack Ent T1557 001 Name Resolution Poisoning And Smb ReAnalyze MITRE ATT&CK T1557.001 Name Resolution Poisoning and SMB Relay in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.001, Name Resolution Poisoning and SMB Relay, or enterprise ATT&CK. By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.(Citation: BlackCat ransomware) This activ…
-
nicshik Skill Perplexity Deep Research 2Perplexity Deep Research for broad multi-source analysis where higher cost and longer runtime are acceptable. Use only when deep research is explicitly justified.
-
anylegal-ai Skill ResearchResearch a legal topic with web search and inline citations. Use when the user needs legal information, market standards, regulatory guidance, or case law references.
-
thewinterdojer Bundle Session InitInitialize a coding session by reading the repo's instructions, execution docs, and current state, then summarize the project and recommend the highest-priority next step. Use when starting work in a repo, when resuming after a handoff, when the user wants a project briefing before coding, or when the user provides a focus area and wants the startup summary biased toward that area.
-
dreamupers Skill Arxiv Paper ReaderRead and summarize arXiv papers from title. Use when the user asks to read/understand an arXiv paper, provides a paper title, or mentions downloading arXiv TeX source (arxiv.org/src). Fetch paper metadata, download and extract source, locate main .tex, read the full paper, and write structured Chinese notes to arxiv_paper_notes using {paper_id}_{method}.md.
-
xicode-ai Bundle Multi Video SummarizerSummarize video/audio content from multiple platforms into structured notes with keyframe screenshots. Supports Bilibili (B站), YouTube, Douyin (抖音), Xiaohongshu (小红书), TikTok, and 1800+ sites via yt-dlp. Triggers on video URLs from any of these platforms, or Chinese requests like '总结视频', '视频笔记', '视频内容'. Detects URLs containing bilibili.com, youtube.com, youtu.be, douyin.com, xiaohongshu.com, tiktok.com, and more.
-
florencevision Skill Research AssistantSystematic research workflows for SOTA AI agents. Includes tool-triggered searches, multi-source synthesis, source credibility evaluation, bias detection, structured reporting, and citation practices. Use for deep research, competitive analysis, literature reviews, due diligence, or any investigation task.
-
anantsharma67 Bundle Repomix WorkflowsWorkflow for using Repomix to compress, structure, summarize, and prepare repositories for AI agents by generating optimized context bundles for reasoning, debugging, code review, and implementation workflows.
-
tyc-tech Skill Tyc Vc Research投资机构画像研究(TYC 独有),聚合机构被投/团队/管理基金/投资动态,输出机构尽调报告
-
tyc-tech Skill Tyc Legal Research法律研究(案例检索 / 法律意见书 / 合规研究)— 关联企业案例自动检索 + 涉诉风险分析
-
tyc-tech Skill Tyc Park Research园区企业研究(TYC 独有),园区画像/入园企业搜索/经纬度雷达/附近公司一站式
Frequently asked questions
What are Research & Search agent skills?
Research agent skills teach AI agents to gather and synthesize information properly: literature reviews, competitive analysis, web research with citations, and structured summaries. Each SKILL.md encodes a method, not just a prompt, so results stay consistent across runs.
Which Research & Search skills are most installed?
Popular Research & Search skills on SkillMD right now include attack-ent-t1127-002-clickonce, attack-ent-t1606-002-saml-tokens, attack-ent-t1136-create-account. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Research & Search skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.