Agent skill

ATT&CK Threat Actor Mapping

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

Apache-2.0Auto-check passedSecurity

Install ATT&CK Threat Actor Mapping

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-threat-actor-ttps-with-mitre-attack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-threat-actor-ttps-with-mitre-attack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-threat-actor-ttps-with-mitre-attack .claude/skills/analyzing-threat-actor-ttps-with-mitre-attack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-threat-actor-ttps-with-mitre-attack
GitHub stars
34k
Token cost
~2.5k tokens
SKILL.md length
366 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

  • Works in 5 steps: Query ATT&CK Data Programmatically → Map Threat Actor to ATT&CK Techniques → Generate ATT&CK Navigator Layer → …
  • Mapping a threat group's observed behavior to ATT&CK techniques
  • SKILL.md covers Overview, When to Use, Prerequisites and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Analysts use this skill to connect what a threat actor does to the MITRE ATT&CK framework. It maps observed behavior and IOCs to specific techniques across the Enterprise, Mobile and ICS matrices, builds coverage heatmaps as ATT&CK Navigator layers, identifies gaps in detection, and writes reports that link indicators to adversary techniques.

The workflow queries ATT&CK data programmatically with the attackcti library, then maps a threat actor to its techniques, and uses Navigator layers, which are JSON files annotating techniques with scores, colors and comments, to visualize actor coverage, detection capability or risk. The background section explains tactics, techniques and sub-techniques, and group profiles with aliases, targeted sectors, software and procedure-level detail.

Prerequisites are Python 3.9 or newer with mitreattack-python, attackcti and stix2, the ATT&CK Navigator, familiarity with STIX 2.1 attack patterns, and threat intelligence from reports or MISP or OpenCTI. The folder ships scripts agent.py and process.py, reference notes on APIs, standards and workflows, and a report template.

When your agent uses it

  • Mapping a threat group's observed behavior to ATT&CK techniques
  • Building a Navigator heatmap of technique coverage
  • Assessing whether current detections cover an adversary's techniques

Example prompts

  • “Map the techniques used by APT29 to ATT&CK and build a Navigator layer.”
  • “Correlate these IOCs from the incident to ATT&CK techniques and list detection gaps.”
  • “Produce a threat intelligence report on FIN7 behavior across the Enterprise matrix.”

Requirements

  • Python 3.9 or newer with mitreattack-python, attackcti and stix2
  • ATT&CK Navigator, web-based or local

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Query ATT&CK Data Programmatically
  2. Map Threat Actor to ATT&CK Techniques
  3. Generate ATT&CK Navigator Layer
  4. Identify Detection Gaps
  5. Cross-Group Technique Comparison

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • attack.mitre.org
    • github.com
    • mitre-attack.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

ATT&CK Threat Actor Mapping loads about 2.5k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 366 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 366 words, ~2,517 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
analyzing-threat-actor-ttps-with-mitre-attack
description
Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.
domain
cybersecurity
subdomain
threat-intelligence
tags
threat-intelligence, cti, ioc, mitre-attack, stix, ttp-analysis, threat-actors
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
Executable Denylisting, Execution Isolation, File Metadata Consistency Validation, Content Format Conversion, File Content Analysis
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02
mitre_attack
T1566.001, T1059.001, T1071.001, T1547.001, T1053.005

Analyzing Threat Actor TTPs with MITRE ATT&CK

Overview

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor behavior to the ATT&CK framework, building technique coverage heatmaps using the ATT&CK Navigator, identifying detection gaps, and producing actionable intelligence reports that link observed IOCs to specific adversary techniques across the Enterprise, Mobile, and ICS matrices.

When to Use

  • When investigating security incidents that require analyzing threat actor ttps with mitre attack
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.9+ with mitreattack-python, attackcti, stix2 libraries
  • MITRE ATT&CK Navigator (web-based or local deployment)
  • Understanding of ATT&CK matrix structure: Tactics, Techniques, Sub-techniques
  • Access to threat intelligence reports or MISP/OpenCTI for threat actor data
  • Familiarity with STIX 2.1 Attack Pattern objects

Key Concepts

ATT&CK Matrix Structure

The ATT&CK Enterprise matrix organizes adversary behavior into 14 Tactics (the "why") containing Techniques (the "how") and Sub-techniques (specific implementations). Each technique has associated data sources, detections, mitigations, and real-world procedure examples from observed threat groups.

Threat Group Profiles

ATT&CK catalogs over 140 threat groups (e.g., APT28, APT29, Lazarus Group, FIN7) with documented technique usage. Each group profile includes aliases, targeted sectors, associated campaigns, software used, and technique mappings with procedure-level detail.

Show full SKILL.md (133 more words)Show less
ATT&CK Navigator

The ATT&CK Navigator is a web-based tool for creating custom ATT&CK matrix visualizations. Analysts create layers (JSON files) that annotate techniques with scores, colors, comments, and metadata to visualize threat actor coverage, detection capabilities, or risk assessments.

Workflow

Step 1: Query ATT&CK Data Programmatically
python
from attackcti import attack_client
import json

# Initialize ATT&CK client (queries MITRE TAXII server)
lift = attack_client()

# Get all Enterprise techniques
enterprise_techniques = lift.get_enterprise_techniques()
print(f"Total Enterprise techniques: {len(enterprise_techniques)}")

# Get all threat groups
groups = lift.get_groups()
print(f"Total threat groups: {len(groups)}")

# Get specific group by name
apt29 = [g for g in groups if 'APT29' in g.get('name', '')]
if apt29:
    group = apt29[0]
    print(f"Group: {group['name']}")
    print(f"Aliases: {group.get('aliases', [])}")
    print(f"Description: {group.get('description', '')[:200]}")
Step 2: Map Threat Actor to ATT&CK Techniques
python
from attackcti import attack_client

lift = attack_client()

# Get techniques used by APT29
apt29_techniques = lift.get_techniques_used_by_group("G0016")  # APT29 group ID

technique_map = {}
for entry in apt29_techniques:
    tech_id = entry.get("external_references", [{}])[0].get("external_id", "")
    tech_name = entry.get("name", "")
    description = entry.get("description", "")
    tactic_refs = [
        phase.get("phase_name", "")
        for phase in entry.get("kill_chain_phases", [])
    ]

    technique_map[tech_id] = {
        "name": tech_name,
        "tactics": tactic_refs,
        "description": description[:300],
    }

print(f"\nAPT29 uses {len(technique_map)} techniques:")
for tid, info in sorted(technique_map.items()):
    print(f"  {tid}: {info['name']} [{', '.join(info['tactics'])}]")
Step 3: Generate ATT&CK Navigator Layer
python
import json

def create_navigator_layer(group_name, technique_map, description=""):
    """Generate ATT&CK Navigator layer JSON for a threat group."""
    techniques_list = []
    for tech_id, info in technique_map.items():
        techniques_list.append({
            "techniqueID": tech_id,
            "tactic": info["tactics"][0] if info["tactics"] else "",
            "color": "#ff6666",  # Red for observed techniques
            "comment": info["description"][:200],
            "enabled": True,
            "score": 100,
            "metadata": [
                {"name": "group", "value": group_name},
            ],
        })

    layer = {
        "name": f"{group_name} TTP Coverage",
        "versions": {
            "attack": "16.1",
            "navigator": "5.1.0",
            "layer": "4.5",
        },
        "domain": "enterprise-attack",
        "description": description or f"Techniques attributed to {group_name}",
        "filters": {"platforms": ["Windows", "Linux", "macOS", "Cloud"]},
        "sorting": 0,
        "layout": {
            "layout": "side",
            "aggregateFunction": "average",
            "showID": True,
            "showName": True,
            "showAggregateScores": False,
            "countUnscored": False,
        },
        "hideDisabled": False,
        "techniques": techniques_list,
        "gradient": {
            "colors": ["#ffffff", "#ff6666"],
            "minValue": 0,
            "maxValue": 100,
        },
        "legendItems": [
            {"label": "Observed technique", "color": "#ff6666"},
            {"label": "Not observed", "color": "#ffffff"},
        ],
        "showTacticRowBackground": True,
        "tacticRowBackground": "#dddddd",
        "selectTechniquesAcrossTactics": True,
        "selectSubtechniquesWithParent": False,
        "selectVisibleTechniques": False,
    }

    return layer


# Generate and save layer
layer = create_navigator_layer("APT29", technique_map, "APT29 (Cozy Bear) TTP analysis")
with open("apt29_navigator_layer.json", "w") as f:
    json.dump(layer, f, indent=2)
print("[+] Navigator layer saved to apt29_navigator_layer.json")
Step 4: Identify Detection Gaps
python
from attackcti import attack_client

lift = attack_client()

# Get all techniques with data sources
all_techniques = lift.get_enterprise_techniques()

# Build data source coverage map
data_source_coverage = {}
for tech in all_techniques:
    tech_id = tech.get("external_references", [{}])[0].get("external_id", "")
    data_sources = tech.get("x_mitre_data_sources", [])

    for ds in data_sources:
        if ds not in data_source_coverage:
            data_source_coverage[ds] = []
        data_source_coverage[ds].append(tech_id)

# Compare threat actor techniques against available detections
detected_techniques = {"T1059", "T1071", "T1566"}  # Example: techniques you can detect
actor_techniques = set(technique_map.keys())

covered = actor_techniques.intersection(detected_techniques)
gaps = actor_techniques - detected_techniques

print(f"\n=== Detection Gap Analysis for APT29 ===")
print(f"Actor techniques: {len(actor_techniques)}")
print(f"Detected: {len(covered)} ({len(covered)/len(actor_techniques)*100:.0f}%)")
print(f"Gaps: {len(gaps)} ({len(gaps)/len(actor_techniques)*100:.0f}%)")
print(f"\nUndetected techniques:")
for tech_id in sorted(gaps):
    if tech_id in technique_map:
        print(f"  {tech_id}: {technique_map[tech_id]['name']}")
Step 5: Cross-Group Technique Comparison
python
from attackcti import attack_client

lift = attack_client()

# Compare techniques across multiple groups
groups_to_compare = {
    "G0016": "APT29",
    "G0007": "APT28",
    "G0032": "Lazarus Group",
}

group_techniques = {}
for gid, gname in groups_to_compare.items():
    techs = lift.get_techniques_used_by_group(gid)
    tech_ids = set()
    for t in techs:
        tid = t.get("external_references", [{}])[0].get("external_id", "")
        if tid:
            tech_ids.add(tid)
    group_techniques[gname] = tech_ids

# Find common and unique techniques
all_groups = list(group_techniques.keys())
common_to_all = set.intersection(*group_techniques.values())
print(f"\nTechniques common to all {len(all_groups)} groups: {len(common_to_all)}")
for tid in sorted(common_to_all):
    print(f"  {tid}")

for gname, techs in group_techniques.items():
    unique = techs - set.union(*[t for n, t in group_techniques.items() if n != gname])
    print(f"\nUnique to {gname}: {len(unique)} techniques")

Validation Criteria

  • ATT&CK data successfully queried via TAXII server or local copy
  • Threat actor mapped to specific techniques with procedure examples
  • ATT&CK Navigator layer JSON is valid and renders correctly
  • Detection gap analysis identifies unmonitored techniques
  • Cross-group comparison reveals shared and unique TTPs
  • Output is actionable for detection engineering prioritization

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/analyzing-threat-actor-ttps-with-mitre-attack of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

ATT&CK Threat Actor Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

ATT&CK Threat Actor Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
ATT&CK Threat Actor Mapping this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Create Sigma RuleTracecatHQ/tracecat3.8k—~16kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Threat Hunt Blueprint AssemblyOTRF/ThreatHunter-Playbook4.7k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Create Sigma Rule

    TracecatHQ/tracecat

    Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…

    3.8k GitHub stars~16k tokensUpdated yesterday
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Threat Hunt Blueprint Assembly

    OTRF/ThreatHunter-Playbook

    Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

    4.7k GitHub stars~1.2k tokensUpdated 9 mo ago
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about ATT&CK Threat Actor Mapping

What does ATT&CK Threat Actor Mapping do?

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports. Analysts use this skill to connect what a threat actor does to the MITRE ATT&CK framework. It maps observed behavior and IOCs to specific techniques across the Enterprise, Mobile and ICS matrices, builds coverage heatmaps as ATT&CK Navigator layers, identifies gaps in detection, and writes reports that link indicators to adversary techniques.

When should I use ATT&CK Threat Actor Mapping?

ATT&CK Threat Actor Mapping fits situations like: mapping a threat group's observed behavior to ATT&CK techniques; building a Navigator heatmap of technique coverage; assessing whether current detections cover an adversary's techniques.

How do I install ATT&CK Threat Actor Mapping in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-threat-actor-ttps-with-mitre-attack -a claude-code`. Or copy the skill folder (skills/analyzing-threat-actor-ttps-with-mitre-attack in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-threat-actor-ttps-with-mitre-attack in your project. Claude Code loads it when a task matches its description.

How do I install ATT&CK Threat Actor Mapping in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-threat-actor-ttps-with-mitre-attack -a codex`. Or copy the skill folder (skills/analyzing-threat-actor-ttps-with-mitre-attack in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-threat-actor-ttps-with-mitre-attack in your project. Codex loads it when a task matches its description.

Can I use ATT&CK Threat Actor Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-threat-actor-ttps-with-mitre-attack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-threat-actor-ttps-with-mitre-attack, .gemini/skills/analyzing-threat-actor-ttps-with-mitre-attack, .github/skills/analyzing-threat-actor-ttps-with-mitre-attack and .opencode/skills/analyzing-threat-actor-ttps-with-mitre-attack in your project.

What does ATT&CK Threat Actor Mapping need to run?

Going by SKILL.md and its folder, ATT&CK Threat Actor Mapping needs Python for the scripts in its folder. Our summary lists: Python 3.9 or newer with mitreattack-python, attackcti and stix2; ATT&CK Navigator, web-based or local.

Does ATT&CK Threat Actor Mapping access the network?

SKILL.md names 3 domains. As links in the text: attack.mitre.org, github.com and mitre-attack.github.io. This is read from the text; nothing was executed.

Is ATT&CK Threat Actor Mapping safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does ATT&CK Threat Actor Mapping use?

ATT&CK Threat Actor Mapping is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does ATT&CK Threat Actor Mapping use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to ATT&CK Threat Actor Mapping?

Skills that share tags, products or a category with ATT&CK Threat Actor Mapping: Security Auditor (eigent-ai/eigent, 15k stars), Create Sigma Rule (TracecatHQ/tracecat, 3.8k stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains ATT&CK Threat Actor Mapping?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.