mitre-attack

Map adversary behavior to ATT&CK techniques for structured threat modeling.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill mitre-attack-drupadsachania
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mitre-attack
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/mitre-attack
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill mitre-attack-drupadsachania

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Map adversary behaviour to ATT&CK techniques to enable structured threat modelling, gap analysis, and guided deception or control design.

Core Features & Use Cases

  • Threat modeling workflow across enterprise and ICS contexts, with phase-based outputs and reference materials.
  • Generates threat models that map techniques to kill chain positions and supports deception engineering and SOC workflows.
  • Use Case: build a top-7 technique profile for a given adversary archetype to prioritise defenses.

Quick Start

Map an adversary archetype to ATT&CK techniques and generate a phase-based threat model.

Frequently Asked Questions about mitre-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map adversary behavior to MITRE ATT&CK techniques for threat modeling?

Threat modeling with MITRE ATT&CK maps adversary behaviors to specific techniques, providing a structured profile of kill chain positions. It enables gap analysis and guides deception or control design across enterprise and ICS security operations.

Can I generate an ATT&CK threat model for ICS environments?

Yes, MITRE ATT&CK threat modeling supports ICS environments alongside enterprise contexts. It maps adversary behaviors to relevant techniques and generates phase-based threat models tailored for industrial control system security operations.

What is the best way to build a threat model for a specific adversary archetype?

Building a threat model for a specific adversary archetype involves mapping their known behaviors to ATT&CK techniques to generate a top-7 technique profile. This structured output prioritizes defenses and supports guided deception engineering.

How does deception engineering integrate with ATT&CK threat modeling?

Deception engineering integrates with ATT&CK threat modeling by using mapped adversary techniques and kill chain positions to guide control design. The generated threat models inform and plan deceptive measures across security operations workflows.

Does ATT&CK threat modeling support multi-phase security operations workflows?

Yes, ATT&CK threat modeling supports multi-phase security operations workflows. It generates structured artifacts and references aligned with kill chain positions, enabling phase-driven outputs for comprehensive threat modeling and deception planning.

Do I need prior threat intelligence data to map adversary behavior to ATT&CK techniques?

You do not need explicit prior threat intelligence data files to map adversary behavior to ATT&CK techniques. You can define an adversary archetype to generate a structured threat model with phase-based outputs and reference materials.