cybersecurity-skills

Align cybersecurity analysis workflows with MITRE ATT&CK and NIST frameworks.

1|1|Updated Apr 9, 2026
One-click install
npx skills add https://github.com/gaoqiongxie/skills-ai --skill cybersecurity-skills
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cybersecurity-skills
Source: https://github.com/gaoqiongxie/skills-ai/tree/main/cybersecurity-skills
Command: npx skills add https://github.com/gaoqiongxie/skills-ai --skill cybersecurity-skills

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security operations teams and cybersecurity analysts face fragmented workflows, inconsistent threat analysis processes, and difficulty aligning security operations with industry-standard frameworks, leading to slower incident response and missed threat detections.

Core Features & Use Cases

  • 754 Structured Security Skills: Covers 26 specialized cybersecurity domains including threat hunting, digital forensics, incident response, penetration testing, malware analysis, and cloud security.
  • Framework Alignment: Maps all skills to 5 major global security frameworks (MITRE ATT&CK v19.1, NIST CSF 2.0, MITRE ATLAS v5.4, MITRE D3FEND v1.3, NIST AI RMF 1.0) for standardized, compliant analysis.
  • Progressive Loading: Uses tiered context loading (500-2000 tokens) to deliver full analysis capabilities without overwhelming the AI's context window.
  • Use Case Example: A SOC analyst can use this skill to investigate a suspected lateral movement incident, map observed behaviors to MITRE ATT&CK techniques, generate detection rules, and produce a standardized incident response report.

Quick Start

Use the cybersecurity-skills tool to investigate a suspected ransomware infection on a company server and generate a full incident response report with containment and remediation steps.

Frequently Asked Questions about cybersecurity-skills

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map threat hunting observations to MITRE ATT&CK techniques?

To map threat hunting observations to MITRE ATT&CK techniques, you can use framework-aligned analysis to standardize detected behaviors and generate structured security outputs. This aligns threat data with global frameworks for consistent tracking.

Can I use this for ransomware incident response and generating a remediation report?

Yes, you can use this for ransomware incident response to investigate suspected infections, map behaviors to security frameworks, and generate a full incident response report with containment and remediation steps.

What security frameworks does this analysis align with for compliance assessment?

This analysis aligns with five major security frameworks for compliance assessment: MITRE ATT&CK v19.1, NIST CSF 2.0, MITRE ATLAS v5.4, MITRE D3FEND v1.3, and NIST AI RMF 1.0. This ensures standardized, compliant operations.

Does this skill support digital forensics and code security auditing?

Yes, this skill supports digital forensics and code security auditing across 26 specialized security domains. It provides structured capabilities to analyze artifacts and audit code for vulnerabilities within a unified workflow.

How do I handle fragmented security operations workflows without overwhelming the context window?

You handle fragmented security operations workflows using progressive context loading, which uses tiered token loading (500-2000 tokens) to deliver full analysis capabilities without overwhelming the AI's context window.