mitre-attack agents

177 tagged mitre-attack, measured the same way as everything else here.

mukul975/Anthropic-Cybersecurity-Skills

Skill Claude CodeCodex

Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback domains, dead drops). Use after reverse engineering reveals network traffic needing protocol analysis or when building…

32k +235 2d ago A 81 tokens original Apache-2.0

AiSOC AGENTS.md

05

beenuar/AiSOC

Instructions file CodexOpenCode

AGENTS.md instructions for beenuar/AiSOC, covering learned user preferences and learned workspace facts.

2.4k 2d ago A 6,497 tokens original MIT

CooperCyberCoffee/opencti_mcp_server

Instructions file

Claude Code instructions for CooperCyberCoffee/opencti_mcp_server, covering cooper cyber coffee opencti mcp server, project overview, recent features (v0.4.2), previous features (v0.4.1 and earlier) and development standards.

29 9mo ago A 704 tokens

meltedinhex/analyst-ai-pack

Instructions file GitHub Copilot

Instructions for meltedinhex/analyst-ai-pack, covering analystaipack — github copilot instructions, how to help in this repo, safety rules (do not violate) and authoring or editing a skill.

22 1mo ago A 704 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Instructions file CodexOpenCode

Instructions for meltedinhex/analyst-ai-pack, covering agents.md — using analystaipack as an ai agent, what this repo is, how to pick a skill, how to run a skill and or directly.

22 1mo ago A 832 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on…

22 1mo ago A 74 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Statically analyzes Linux ELF malware: ELF header and sections, dynamic symbols and imports, segment permissions, embedded strings, and packing indicators to infer capability without execution. Activates for requests to analyze an ELF binary, Linux malware, or shared object.

22 1mo ago A 59 tokens original Apache-2.0

meltedinhex/analyst-ai-pack

Skill Claude CodeCodex

Analyzes weaponized Windows shortcut (.lnk) files: parsing the shell link structure for the target command, arguments, icon, and working directory, and recovering hidden PowerShell/cmd payloads and embedded content used in phishing. Activates for requests to analyze a malicious LNK, parse a shortcut file, or extract a…

22 1mo ago A 81 tokens original Apache-2.0

show-matrix

14

ayuksel-tenb/tenable-attack-mapper

Skill Claude CodeCodex

Clone the attack-navigator viewer, map this Security Center's open findings to MITRE ATT&CK, bring the viewer up, and open the VPR-scored ATT&CK matrix in the browser. Use when the user asks to show / open / visualize the ATT&CK matrix or their exposure, e.g. "open the attack matrix", "show me the ATT&CK matrix".

5 2mo ago A 83 tokens original MIT

attack-mapper

15

ayuksel-tenb/tenable-attack-mapper

Agent

Threat-informed vulnerability analyst. Maps Tenable Security Center findings to MITRE ATT&CK techniques and produces a VPR-scored Navigator layer. Use when the user asks which ATT&CK tactics/techniques to watch, which findings map to a technique, or to export an ATT&CK Navigator coverage layer.

5 2mo ago A 66 tokens original MIT

mitre-mcp AGENTS.md

16

lidless-labs/mitre-mcp

Instructions file CodexOpenCode

Instructions for lidless-labs/mitre-mcp, covering repository guidance, definition of done, project shape, verification workflow and soc safety (hard prohibitions).

4 24d ago A 1,139 tokens original MIT

haporfirio/cyberskills-hub

Instructions file

Instructions for haporfirio/cyberskills-hub, covering cyberskills documentation hub, instrucao de routing, role context, top-50 keywords and domain lookup.

2 5mo ago A 1,452 tokens original MIT

pentest-mcp-server

18

cyanheads/pentest-mcp-server

Plugin Claude Code

Offline methodology engine and payload workshop for authorized penetration testing, CTF, security research, and education.

1 11d ago A tokens not measured copy · 91% Apache-2.0

cyanheads/pentest-mcp-server

Instructions file CodexOpenCode

AGENTS.md instructions for cyanheads/pentest-mcp-server, covering developer protocol, core rules, patterns, tool (representative — pentestlookuptechnique) and server instructions.

1 11d ago A 5,192 tokens copy · 73% Apache-2.0

cyanheads/pentest-mcp-server

Instructions file

Claude Code instructions for cyanheads/pentest-mcp-server, covering developer protocol, core rules, patterns, tool (representative — pentestlookuptechnique) and server instructions.

1 11d ago A 5,192 tokens copy · 73% Apache-2.0

add-tool

21

cyanheads/pentest-mcp-server

Skill Claude CodeCodex

Scaffold a new MCP tool definition. Use when the user asks to add a tool, create a new tool, or implement a new capability for the server.

1 11d ago A 35 tokens copy · 100% Apache-2.0

design-mcp-server

22

cyanheads/pentest-mcp-server

Skill Claude CodeCodex

Design the tool surface, resources, and service layer for a new MCP server. Use when starting a new server, planning a major feature expansion, or when the user describes a domain/API they want to expose via MCP. Produces a design doc at docs/design.md that drives implementation.

1 11d ago A 62 tokens copy · 100% Apache-2.0

release-and-publish

23

cyanheads/pentest-mcp-server

Skill Claude CodeCodex

Ship a release end-to-end across every registry the project targets (npm, MCP Registry, GitHub Releases for .mcpb bundles, GHCR). Runs the final verification gate, pushes commits and tags, then publishes to each applicable destination. Assumes git wrapup (version bumps, changelog, commit, annotated tag) is already…

1 11d ago A 112 tokens copy · 92% Apache-2.0

pentest-mcp-server

24

cyanheads/pentest-mcp-server

MCP server Claude CodeCodexCursor

Offline methodology engine for authorized penetration testing, CTF, and security research. Runs locally from the @cyanheads/pentest-mcp-server npm package. Needs 1 environment variable to run.

1 11d ago A tokens not measured original Apache-2.0

At most 3 mods per repository are shown here — the rest are on their repository pages: