mitre-attack
49Skill Claude Code needs its repo
MITRE ATT&CK local dataset reference. Query techniques, groups, software, and mitigations from the local enterprise-attack.json.
Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.
This repository also configures its own agents. See what cti-skills tells them →
Skill Claude Code needs its repo
MITRE ATT&CK local dataset reference. Query techniques, groups, software, and mitigations from the local enterprise-attack.json.
Skill Claude Code
Structured OSINT collection methodology. Planning, collection techniques, search operators, and documentation. Loaded by the osint-researcher agent.
Skill Claude Code
AlienVault OTX API reference. Community threat intelligence pulses and indicator lookups.
Skill Claude Code
Use when the user asks about phishing campaigns, social-engineering techniques, BEC (business email compromise), pretexting, AiTM (adversary-in-the-middle) kits, or specific phishing-kit families. Self-updating knowledge cell.
Skill Claude Code
Use when the user asks to create, review, retire, or refine Priority Intelligence Requirements, or wants to align collection and analysis to the current PIR set. Covers the PIR lifecycle end-to-end.
Skill Claude Code
Peer review checklist and quality standards for intelligence products. Loaded by the quality-reviewer agent.
Skill Claude Code
Use when the user asks about the ransomware ecosystem, RaaS dynamics, affiliate markets, attribution between groups, leak-site behaviour, or recent group activity (LockBit lineage, ALPHV/BlackCat, RansomHub, Akira, Play, Qilin, Cl0p, Medusa, etc.). Self-updating knowledge cell.
Skill Claude Code
Use when challenging a prevailing analytical judgment, the user asks "what is the opposing case?" / "argue the other side", or wants a devil's-advocate review of an assessment. Deliberately argues the opposite position to expose weaknesses.
Skill Claude Code
ReversingLabs Spectra Analyze (A1000) API reference. File hash classification, detailed reports, dynamic analysis, network indicator reputation, advanced search, YARA, container relationships.
Skill Claude Code
Use when the user asks about Russian state-sponsored cyber operations or specific actors (APT28/Fancy Bear, Sandworm, Cozy Bear/APT29, Turla, GRU-affiliated hacktivist fronts like CARR/NoName057), wartime ICS/OT campaigns, or pro-RU information operations. Self-updating knowledge cell.
Skill Claude Code
Shodan API reference. Host reconnaissance, port scanning, and vulnerability data.
Skill Claude Code
Use when the user asks for a SIGMA detection rule, "write a SIGMA rule for X", or /hash-investigation / /malware-analysis surfaces behaviour worth a vendor-agnostic detection. Format spec + writing guide.
Skill Claude Code
Use when the user asks about CTI standard operating procedures (daily triage, IOC processing, flash-report cadence, threat-actor profile updates, briefing schedule), or wants to look up a specific SOP.
Skill Claude Code
Use when rating a source with the NATO Admiralty Scale, the user asks "is this reliable?" / "rate this source", or the tradecraft pipeline calls for source assessment before publishing. Reliability A-F, credibility 1-6.
Skill Claude Code
Use when the user asks "who are our customers?" / "how do we tailor for X stakeholder?" / "who should this report go to?", or wants to map / re-map stakeholder needs. Ensures intelligence reaches the right people in the right format.
Skill Claude Code
STIX 2.1 bundle creation reference. Object types, relationships, and JSON templates for structured threat intelligence sharing.
Skill Claude Code
Use when the user asks "which SAT should I use for X?", wants the index of Structured Analytic Techniques, or is choosing between ACH, key-assumptions-check, red-team-analysis, indicators of change, etc.
Skill Claude Code
Use when the user asks about supply-chain attacks, third-party / vendor compromise (SolarWinds, Kaseya, 3CX, MOVEit, XZ-utils-style), software-bill-of-materials risks, or library / dependency-injection attacks. Self-updating knowledge cell.
Skill Claude Code
Use when the user asks to build or update a threat-actor profile, "tell me about actor X" / "profile actor Y", or another skill needs the canonical profile template (attribution, TTPs, campaigns, infrastructure patterns, intelligence gaps).
Skill Claude Code
Structured threat assessment methodology. Intent + Capability + Opportunity = Threat Level. Use when formally evaluating a threat.
Skill Claude Code
Use when the user asks "what TLP should this be?", applying TLP markings to a finished product, or the tradecraft pipeline calls for TLP determination before sharing. Covers TLP v2.0 (CLEAR / GREEN / AMBER / AMBER+STRICT / RED).
Skill Claude CodeCodex
Use when a user asks to scan, investigate, or characterize a URL. Submits to URLScan (unlisted by default), cross-references with VirusTotal and OTX, extracts the parent domain and resolved IP for follow-up investigation. Returns verdict, redirect chain, contacted infrastructure, and screenshot. Invoked by…
Skill Claude Code
URLScan.io API reference. URL submission, scanning, and result retrieval.
Skill Claude Code
VirusTotal API v3 reference. File, IP, domain, and URL analysis endpoints.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: