KubeShark for Kubernetes
LukasNiessen/kubernetes-skill
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
Agent skill
Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .claude/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .claude/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .agents/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .agents/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .cursor/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .cursor/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/designing-adversary-engagement-with-mitre-engage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .gemini/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .gemini/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .github/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .github/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .opencode/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "designing-adversary-engagement-with-mitre-engage" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/designing-adversary-engagement-with-mitre-engage into .opencode/skills/designing-adversary-engagement-with-mitre-engage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "designing-adversary-engagement-with-mitre-engage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
designing-adversary-engagement-with-mitre-engagePlan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.
Designing Adversary Engagement With Mitre Engage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare, Expose, Affect, Elicit, Understand), the 10-Step Operational Process, mapping engagement Activities to the ATT&CK techniques they expose, and defining measurable Goals and Operational Objectives. Use when a team has honeypots, honeytokens, or canary tokens but no coordinating strategy, when leadership asks "should…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).
It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
engage.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designing Adversary Engagement With Mitre Engage loads about 3k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,330 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,330 words, ~2,952 tokens.
.claude/skills/designing-adversary-engagement-with-mitre-engage/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.This skill is the strategy and operations layer that sits above tactical deployment skills (honeypot, honeytoken, canary-token, and decoy-file deployment). Use those skills to implement the Activities this skill selects and sequences.
Engage operations follow the 10-Step Operational Process. The matrix is linear to read but cyclical to run — you continuously realign Activities toward your Goals as the adversary reacts.
Decide where denial, deception, and adversary engagement fit in the existing cyber strategy. The Prepare goal (a strategic bookend, alongside Understand) defines the inputs to the operation. Document the strategic goal in plain language, e.g. "reduce dwell time of insider threats around the source-code repository" or "generate first-party CTI on the actor targeting our VPN."
Select from the three Engagement Goals. Goals set direction; Operational Objectives take measurable steps in that direction.
| Engagement Goal (EGO) | What it does | Example Operational Objective |
|---|---|---|
| Expose | Reveal adversary presence with high-fidelity, low-false-positive alerts | "Alert within 5 minutes of any touch on a decoy credential" |
| Affect | Negatively change the adversary's cost-value calculation (defender network only) | "Redirect the adversary away from 3 unpatchable legacy hosts" |
| Elicit | Observe the adversary to learn TTPs and produce CTI | "Obtain a second-stage malware sample" or "identify ≥10 new indicators" |
Write objectives as falsifiable, time-bound statements. A goal without an objective is unmeasurable.
For each Goal, pick the Engagement Approaches (EAP) that fit the adversary you modeled:
For each technique your target adversary uses, find the Engage Activity that exposes the weakness that technique creates. Example mappings:
| Adversary technique (ATT&CK) | Weakness exposed | Engage Activity (EAC) |
|---|---|---|
| T1078 Valid Accounts | Must test credentials | Decoy Credentials, Lures |
| T1083 File & Directory Discovery | Must enumerate files | Decoy Content, Pocket Litter |
| T1046 Network Service Discovery | Must scan the network | Network Diversity, Decoy Systems |
| T1021 Remote Services | Must move laterally | Decoy Systems, Network Manipulation |
| T1552 Unsecured Credentials | Harvests secrets | Decoy Credentials, Artifact Diversity |
Pull the authoritative Activity list and IDs from the live matrix; Engage IDs use the prefixes SGO/EGO (Goals), SAP/EAP (Approaches), and SAC/EAC (Activities).
Decide realism and isolation. Choose between standalone, connected, or integrated decoy environments (see D3FEND honeynet types in references/standards.md). Populate it with diverse, believable artifacts — Persona Creation, Pocket Litter, Artifact Diversity, Application Diversity — so the environment survives adversary scrutiny.
Document, before deployment: what the adversary is allowed to reach, the maximum blast radius, the trigger for tear-down or hand-off to IR, evidence preservation steps, and who has authority to escalate. Affect Activities are limited to the defender's own network — never act on infrastructure you do not own.
Implement the selected Activities using the tactical deployment skills (honeypots, honeytokens, canary tokens, decoy files). Instrument every artifact so a touch produces telemetry routed to the SOC.
Run the operation. Triage Expose alerts as high-fidelity (a touch on a decoy almost always means malicious or unauthorized activity). Feed observations back into Approach selection — realign Affect/Elicit Activities as the adversary behaves.
The Understand goal (the output bookend) turns observations into decisions: new detections for production, CTI for sharing, and validated or invalidated threat-model assumptions.
Score the operation against the Operational Objectives from Step 2. Capture what intel was gained, what Activities triggered, dwell time, and lessons learned. Update the threat model and feed the next cycle.
| Concept | Definition |
|---|---|
| Goal (SGO/EGO) | High-level outcome of the operation. Prepare/Understand are strategic bookends; Expose/Affect/Elicit are the engagement goals. |
| Approach (SAP/EAP) | The method used to make progress toward a Goal (e.g., Detection, Direction, Motivation). |
| Activity (SAC/EAC) | The concrete denial/deception action deployed (e.g., Decoy Credentials, Network Manipulation). |
| Operate | The default matrix view = Expose + Affect + Elicit, the three engagement goals. |
| Operational Objective | A measurable, time-bound target that operationalizes a Goal. |
| Gating Criteria | Pre-defined boundaries and triggers that constrain the operation's blast radius. |
| High-fidelity alert | An alert from a decoy that legitimate users have no reason to touch, yielding near-zero false positives. |
| Denial vs. Deception | Denial blocks the adversary's access to real information; deception feeds plausible false information. |
Deceive tactic provides defensive countermeasure naming (Decoy Environment, Decoy Object, honeynet types) that complements Engage.Produce an Adversary Engagement Operation Plan using assets/template.md, containing:
Use scripts/process.py to validate technique→Activity coverage and generate the operation-plan skeleton from a threat-model input.
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/designing-adversary-engagement-with-mitre-engage of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Designing Adversary Engagement With Mitre Engage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Designing Adversary Engagement With Mitre Engage this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| KubeShark for KubernetesLukasNiessen/kubernetes-skill | 446 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Dependency Auditoralirezarezvani/claude-code-tresor | 777 | — | ~1.2k | Automated safety check: Notes | MIT | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 156 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Robotics Securityarpitg1304/robotics-agent-skills | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | |
| Canary Tripwire Responsedeonmenezes/mantishack | 503 | — | ~376 | Automated safety check: Pass | Apache-2.0 |
LukasNiessen/kubernetes-skill
Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.
alirezarezvani/claude-code-tresor
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
arpitg1304/robotics-agent-skills
Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.
deonmenezes/mantishack
What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result
cloudposse/atmos
Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Designing Adversary Engagement With Mitre Engage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.
Designing Adversary Engagement With Mitre Engage fits situations like: A team has honeypots; canary tokens but no coordinating strategy; leadership asks should we engage attackers and how; building a deception/denial program.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a claude-code`. Or copy the skill folder (skills/designing-adversary-engagement-with-mitre-engage in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/designing-adversary-engagement-with-mitre-engage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a codex`. Or copy the skill folder (skills/designing-adversary-engagement-with-mitre-engage in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/designing-adversary-engagement-with-mitre-engage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/designing-adversary-engagement-with-mitre-engage, .gemini/skills/designing-adversary-engagement-with-mitre-engage, .github/skills/designing-adversary-engagement-with-mitre-engage and .opencode/skills/designing-adversary-engagement-with-mitre-engage in your project.
Going by SKILL.md and its folder, Designing Adversary Engagement With Mitre Engage needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: engage.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Designing Adversary Engagement With Mitre Engage is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Designing Adversary Engagement With Mitre Engage: KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 446 stars), Dependency Auditor (alirezarezvani/claude-code-tresor, 777 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars) and Robotics Security (arpitg1304/robotics-agent-skills, 369 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.