redteam-recon-nation

Correlate state-sponsored APT activity and map TTPs to MITRE ATT&CK.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-recon-nation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-recon-nation
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/redteam-recon-nation
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-recon-nation

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

国家级APT活动的识别与关联困难,导致对威胁的响应迟缓。本技能提供系统化的跨源情报分析,帮助将目标、行动和时间线拼接成可执行的威胁情报。

Core Features & Use Cases

  • APT追踪与画像:识别国家背后势力及其活动特征
  • 战术分析与TTP映射:将攻击手法、技术与程序对齐MITRE ATT&CK框架
  • 地缘政治关联:将事件与地缘政治进程联系起来
  • IOC提取与报告生成:提取域名/哈希等指标,输出可导入的情报格式

Quick Start

请提供目标APT名称或地缘政治情境,以生成完整的威胁情报分析。

Frequently Asked Questions about redteam-recon-nation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map APT attack techniques to the MITRE ATT&CK framework?

To map APT attack techniques to the MITRE ATT&CK framework, provide the target APT name or geopolitical context to generate a structured threat intelligence profile aligning tactics, techniques, and procedures.

What is the best way to correlate state-sponsored threat intelligence across geopolitical contexts?

Correlating state-sponsored threat intelligence involves identifying APT activities, linking them to geopolitical processes, and mapping attack chains to produce actionable national threat intelligence reports.

How do I extract IOCs from open-source data for threat analysis?

Extracting IOCs from open-source data is done by analyzing state-sponsored APT activity to identify domains and hashes, outputting them in an importable intelligence format for security operations.

Can I generate target profiles for state-sponsored APT groups?

Yes, you can generate target profiles for state-sponsored APT groups by providing the APT name or geopolitical scenario to identify threat actors and their specific activity characteristics.

Does this analysis support phase-based workflows for security operations centers?

Yes, this analysis supports phase-based workflows for security operations centers by mapping TTPs to MITRE ATT&CK and extracting IOCs to accelerate target profiling and attack chain mapping.