analyzing-cyber-kill-chain

mukul975/analyzing-cyber-kill-chain · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Maps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.7 KB
  • 📁scripts
  • ⚙️agent.py 10.2 KB
  • 📄LICENSE 11.0 KB

Related

  1. threat-analyst · drnabeelkhan
    Monitors authorized threat intelligence feeds and maps adversary TTPs to MITRE ATT&CK, NIST CSF, and ISO 27001 frameworks to produce actionable intelligence reports with IOCs and defensive recommendations.
    2
    repo stars
  2. security-threat-intelligence · drnabeelkhan bundle
    Routes security, compliance, and threat-intelligence tasks to specialized sub-skills for threat modeling, penetration testing, incident response, and vulnerability scanning.
    2
    repo stars
  3. implementing-diamond-model-analysis · mukul975 bundle
    Provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    24.6k
    repo stars
  4. conducting-malware-incident-response · mukul975 bundle
    Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures.
    24.6k
    repo stars
  5. triaging-security-alerts-in-splunk · mukul975 bundle
    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard.
    24.6k
    repo stars
  6. analyzing-windows-amcache-artifacts · mukul975 bundle
    Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations.
    24.6k
    repo stars

Frequently asked questions

How do I install the analyzing-cyber-kill-chain skill?

Run npx skillmds add mukul975/analyzing-cyber-kill-chain in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the analyzing-cyber-kill-chain skill do?

Maps intrusion activity to the Lockheed Martin Cyber Kill Chain framework to identify adversary phase completion, detection gaps, and defensive controls for post-incident analysis and prevention. It is listed under Security, Incident Response on SkillMD.

Is analyzing-cyber-kill-chain safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with analyzing-cyber-kill-chain?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is analyzing-cyber-kill-chain free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published analyzing-cyber-kill-chain?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.