mapping-attack-techniques
Installation
SKILL.md
Mapping ATT&CK Techniques
ATT&CK is a shared vocabulary, not a methodology. Its value is that offense, detection, and response can name the same behaviour — which makes this skill a router, not a technique catalogue. It resolves a technique to the skill that holds the actual procedure, and it runs the loop that connects the two sides.
When to Use
- A request names a technique ID (
T1003.001), a technique name ("Kerberoasting"), or a tactic ("we need lateral movement coverage") - Converting a threat intel report or an adversary emulation plan into work
- Planning or reporting coverage against the matrix
- Running a purple team exercise: emulate, detect, validate, close the gap
- Choosing which skill applies when a request spans offense and defense