building-attack-pattern-library-from-cti-reports

mukul975/building-attack-pattern-library-from-cti-reports · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.4 KB
  • 📁scripts
  • ⚙️agent.py 5.1 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-stix-taxii-feed-integration · mukul975 bundle
    Consume and produce STIX/TAXII 2.1 cyber threat intelligence feeds using Python, including server discovery, collection polling, object parsing, and SIEM/TIP integration.
    24.6k
    repo stars
  2. malware-analysis · zhaoxuya520 bundle
    Analyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
    12.8k
    repo stars
  3. modeling-threats-with-opencti · mukul975 bundle
    Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
    24.6k
    repo stars
  4. managing-intelligence-lifecycle · mukul975 bundle
    Guides the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to establish or mature a CTI program.
    24.6k
    repo stars
  5. mapping-mitre-attack-techniques · mukul975 bundle
    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.
    24.6k
    repo stars
  6. analyzing-apt-group-with-mitre-navigator · mukul975 bundle
    Query MITRE ATT&CK data programmatically, map APT group TTPs to Navigator layers, create multi-layer overlays for gap analysis, and generate actionable intelligence reports for detection engineering teams.
    24.6k
    repo stars

Frequently asked questions

How do I install the building-attack-pattern-library-from-cti-reports skill?

Run npx skillmds add mukul975/building-attack-pattern-library-from-cti-reports in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the building-attack-pattern-library-from-cti-reports skill do?

Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library mapped to MITRE ATT&CK for detection engineering and threat-informed defense. It is listed under Security on SkillMD.

Is building-attack-pattern-library-from-cti-reports safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with building-attack-pattern-library-from-cti-reports?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is building-attack-pattern-library-from-cti-reports free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published building-attack-pattern-library-from-cti-reports?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.