mapping-attack-techniques

Installation
SKILL.md

Mapping ATT&CK Techniques

ATT&CK is a shared vocabulary, not a methodology. Its value is that offense, detection, and response can name the same behaviour — which makes this skill a router, not a technique catalogue. It resolves a technique to the skill that holds the actual procedure, and it runs the loop that connects the two sides.

When to Use

  • A request names a technique ID (T1003.001), a technique name ("Kerberoasting"), or a tactic ("we need lateral movement coverage")
  • Converting a threat intel report or an adversary emulation plan into work
  • Planning or reporting coverage against the matrix
  • Running a purple team exercise: emulate, detect, validate, close the gap
  • Choosing which skill applies when a request spans offense and defense

When NOT to Use

Installs
24
GitHub Stars
146
First Seen
Jul 30, 2026
mapping-attack-techniques — trilwu/secskills