Agent skill

Implementing Threat Modeling With Mitre Attack

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

Apache-2.0Auto-check passedSecurity

Install Implementing Threat Modeling With Mitre Attack

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-threat-modeling-with-mitre-attack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-threat-modeling-with-mitre-attack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-threat-modeling-with-mitre-attack .claude/skills/implementing-threat-modeling-with-mitre-attack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-threat-modeling-with-mitre-attack
GitHub stars
34k
Token cost
~3.4k tokens
SKILL.md length
447 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

  • Works in 6 steps: Identify Relevant Threat Actors → Build Threat Actor TTP Profile → Map Current Detection Coverage → …
  • SOC teams need to align detection engineering with threat landscape
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches raw.githubusercontent.com

What it does

Implementing Threat Modeling With Mitre Attack is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Threat modeling, Security operations and Test coverage. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • SOC teams need to align detection engineering with threat landscape
  • Conduct threat assessments for new environments
  • Justify security tool procurement

Example prompts

  • “Use the implementing-threat-modeling-with-mitre-attack skill to implement threat modeling using the MITRE ATT&CK framework to map adversary TTPs…”
  • “/implementing-threat-modeling-with-mitre-attack”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Relevant Threat Actors
  2. Build Threat Actor TTP Profile
  3. Map Current Detection Coverage
  4. Perform Gap Analysis
  5. Create Prioritized Remediation Plan
  6. Validate with Adversary Emulation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Threat Modeling With Mitre Attack loads about 3.4k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 447 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 447 words, ~3,370 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-threat-modeling-with-mitre-attack/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-threat-modeling-with-mitre-attack
description
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.
domain
cybersecurity
subdomain
soc-operations
tags
soc, mitre-attack, threat-modeling, ttp, detection-coverage, attack-navigator, risk-assessment
version
1.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
d3fend_techniques
File Metadata Consistency Validation, Application Protocol Command Analysis, Identifier Analysis, Content Format Conversion, Message Analysis
nist_csf
DE.CM-01, DE.AE-02, RS.MA-01, DE.AE-06

Implementing Threat Modeling with MITRE ATT&CK

When to Use

Use this skill when:

  • SOC teams need to assess detection coverage against relevant threat actors and their TTPs
  • Security leadership requires threat-informed defense prioritization
  • New environments (cloud migration, OT integration) need detection strategy planning
  • Purple team exercises require structured adversary emulation based on threat models
  • Annual risk assessments need ATT&CK-based threat landscape analysis

Do not use as a one-time exercise — threat models must be continuously updated as adversary TTPs evolve and organizational attack surface changes.

Prerequisites

  • MITRE ATT&CK framework knowledge (Enterprise, ICS, Mobile, or Cloud matrices)
  • ATT&CK Navigator tool (web or local) for layer visualization
  • Current detection rule inventory mapped to ATT&CK technique IDs
  • Threat intelligence on adversary groups targeting your sector
  • Organizational asset inventory with criticality classifications

Workflow

Step 1: Identify Relevant Threat Actors

Research adversary groups targeting your sector using MITRE ATT&CK Groups:

python
import requests
import json

# Download ATT&CK STIX data
response = requests.get(
    "https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json"
)
attack_data = response.json()

# Extract groups and their techniques
groups = {}
for obj in attack_data["objects"]:
    if obj["type"] == "intrusion-set":
        group_name = obj["name"]
        aliases = obj.get("aliases", [])
        description = obj.get("description", "")
        groups[group_name] = {
            "aliases": aliases,
            "description": description[:200],
            "techniques": []
        }

# Map techniques to groups via relationships
relationships = [obj for obj in attack_data["objects"] if obj["type"] == "relationship"]
techniques = {obj["id"]: obj for obj in attack_data["objects"]
              if obj["type"] == "attack-pattern"}

for rel in relationships:
    if rel["relationship_type"] == "uses":
        source = rel["source_ref"]
        target = rel["target_ref"]
        for group_name, group_data in groups.items():
            if source == group_data.get("id") and target in techniques:
                tech = techniques[target]
                ext_refs = tech.get("external_references", [])
                for ref in ext_refs:
                    if ref.get("source_name") == "mitre-attack":
                        group_data["techniques"].append(ref["external_id"])

# Example: Financial sector threat actors
financial_actors = ["FIN7", "FIN8", "Carbanak", "APT38", "Lazarus Group"]
for actor in financial_actors:
    if actor in groups:
        print(f"{actor}: {len(groups[actor]['techniques'])} techniques")
        print(f"  Top techniques: {groups[actor]['techniques'][:10]}")
Step 2: Build Threat Actor TTP Profile

Create ATT&CK Navigator layers for priority threat actors:

python
import json

def create_attack_layer(actor_name, techniques, color="#ff6666"):
    """Generate ATT&CK Navigator JSON layer for a threat actor"""
    layer = {
        "name": f"{actor_name} TTP Profile",
        "versions": {
            "attack": "15",
            "navigator": "5.0",
            "layer": "4.5"
        },
        "domain": "enterprise-attack",
        "description": f"Techniques associated with {actor_name}",
        "techniques": [
            {
                "techniqueID": tech_id,
                "tactic": "",
                "color": color,
                "comment": f"Used by {actor_name}",
                "enabled": True,
                "score": 1
            }
            for tech_id in techniques
        ],
        "gradient": {
            "colors": ["#ffffff", color],
            "minValue": 0,
            "maxValue": 1
        }
    }
    return layer

# Create layers for top threat actors
fin7_techniques = ["T1566.001", "T1059.001", "T1053.005", "T1547.001",
                    "T1078", "T1021.001", "T1003", "T1071.001", "T1041"]
layer = create_attack_layer("FIN7", fin7_techniques, "#ff6666")

with open("fin7_layer.json", "w") as f:
    json.dump(layer, f, indent=2)
Step 3: Map Current Detection Coverage

Export current detection rules mapped to ATT&CK:

spl
--- Extract ATT&CK technique mappings from Splunk ES correlation searches
| rest /services/saved/searches
  splunk_server=local
| where match(title, "^(COR|ESCU|RBA):")
| eval techniques = if(isnotnull(action.correlationsearch.annotations),
                       spath(action.correlationsearch.annotations, "mitre_attack"),
                       "unmapped")
| stats count by techniques
| mvexpand techniques
| stats count by techniques
| rename techniques AS technique_id, count AS rule_count

Create detection coverage layer:

python
def create_coverage_layer(detection_rules):
    """Generate coverage layer from detection rule inventory"""
    technique_counts = {}
    for rule in detection_rules:
        for tech in rule.get("techniques", []):
            technique_counts[tech] = technique_counts.get(tech, 0) + 1

    layer = {
        "name": "SOC Detection Coverage",
        "versions": {"attack": "15", "navigator": "5.0", "layer": "4.5"},
        "domain": "enterprise-attack",
        "techniques": [
            {
                "techniqueID": tech_id,
                "color": "#31a354" if count >= 2 else "#a1d99b" if count == 1 else "",
                "score": count,
                "comment": f"{count} detection rule(s)"
            }
            for tech_id, count in technique_counts.items()
        ],
        "gradient": {
            "colors": ["#ffffff", "#a1d99b", "#31a354"],
            "minValue": 0,
            "maxValue": 3
        }
    }
    return layer
Step 4: Perform Gap Analysis

Overlay threat actor TTPs against detection coverage:

python
def gap_analysis(threat_techniques, covered_techniques):
    """Identify detection gaps for specific threat actor"""
    gaps = set(threat_techniques) - set(covered_techniques)
    covered = set(threat_techniques) & set(covered_techniques)

    print(f"Threat Actor Techniques: {len(threat_techniques)}")
    print(f"Detected: {len(covered)} ({len(covered)/len(threat_techniques)*100:.0f}%)")
    print(f"Gaps: {len(gaps)} ({len(gaps)/len(threat_techniques)*100:.0f}%)")

    # Prioritize gaps by kill chain phase
    priority_order = {
        "TA0001": 1, "TA0002": 2, "TA0003": 3, "TA0004": 4,
        "TA0005": 5, "TA0006": 6, "TA0007": 7, "TA0008": 8,
        "TA0009": 9, "TA0010": 10, "TA0011": 11, "TA0040": 12
    }

    gap_details = []
    for tech_id in gaps:
        gap_details.append({
            "technique": tech_id,
            "priority": "HIGH" if tech_id.split(".")[0] in ["T1003", "T1021", "T1059"] else "MEDIUM",
            "recommendation": f"Build detection for {tech_id}"
        })

    return {
        "total_actor_techniques": len(threat_techniques),
        "covered": len(covered),
        "gaps": len(gaps),
        "coverage_pct": round(len(covered)/len(threat_techniques)*100, 1),
        "gap_details": sorted(gap_details, key=lambda x: x["priority"])
    }

# Run analysis
result = gap_analysis(fin7_techniques, current_coverage)
Step 5: Create Prioritized Remediation Plan

Build a detection engineering roadmap:

yaml
threat_model_remediation_plan:
  assessed_date: 2024-03-15
  primary_threats:
    - FIN7 (Financial sector)
    - APT38 (DPRK financial)
    - Lazarus Group (Destructive)

  current_coverage: 64%
  target_coverage: 80%

  priority_1_gaps: # 30-day target
    - technique: T1021.002
      name: SMB/Windows Admin Shares
      data_source: Windows Security Event 5140
      effort: Low
      detection_approach: Monitor admin share access from non-admin workstations

    - technique: T1003.006
      name: DCSync
      data_source: Windows Security Event 4662
      effort: Medium
      detection_approach: Detect DS-Replication-Get-Changes from non-DC sources

  priority_2_gaps: # 60-day target
    - technique: T1055
      name: Process Injection
      data_source: Sysmon EventCode 8, 10
      effort: High
      detection_approach: Monitor cross-process memory access patterns

    - technique: T1071.001
      name: Web Protocols (C2)
      data_source: Proxy/Firewall logs
      effort: Medium
      detection_approach: Detect beaconing patterns in HTTP/S traffic

  priority_3_gaps: # 90-day target
    - technique: T1070.004
      name: File Deletion
      data_source: Sysmon EventCode 23
      effort: Low
      detection_approach: Monitor mass file deletion in sensitive directories
Step 6: Validate with Adversary Emulation

Test coverage using MITRE Caldera or Atomic Red Team:

bash
# Using Atomic Red Team to validate coverage for FIN7 techniques
# T1566.001 — Spearphishing Attachment
Invoke-AtomicTest T1566.001

# T1059.001 — PowerShell
Invoke-AtomicTest T1059.001 -TestNumbers 1,2,3

# T1053.005 — Scheduled Task
Invoke-AtomicTest T1053.005

# T1547.001 — Registry Run Keys
Invoke-AtomicTest T1547.001

# T1003 — Credential Dumping
Invoke-AtomicTest T1003 -TestNumbers 1,2

# Verify detections
# Check SIEM for corresponding alerts within 15 minutes

Document emulation results to validate threat model accuracy.

Key Concepts

TermDefinition
MITRE ATT&CKKnowledge base of adversary tactics, techniques, and procedures based on real-world observations
TTPTactics, Techniques, and Procedures — the behavioral patterns of adversary groups
ATT&CK NavigatorWeb tool for visualizing ATT&CK matrices as layered heatmaps showing coverage or threat profiles
Gap AnalysisProcess of comparing threat actor TTPs against detection coverage to identify blind spots
Threat-Informed DefenseSecurity strategy prioritizing defenses based on actual adversary behaviors rather than theoretical risks
Adversary EmulationControlled simulation of threat actor TTPs to validate detection and response capabilities
Show full SKILL.md (136 more words)Show less

Tools & Systems

  • MITRE ATT&CK Navigator: Web-based visualization tool for creating and overlaying ATT&CK technique layers
  • MITRE Caldera: Automated adversary emulation platform for testing detection coverage at scale
  • Atomic Red Team: Open-source library of ATT&CK technique tests for security control validation
  • CTID ATT&CK Workbench: MITRE tool for customizing ATT&CK knowledge base with organizational context
  • Tidal Cyber: Commercial platform for threat-informed defense planning using ATT&CK framework

Common Scenarios

  • Annual Threat Assessment: Map top 5 threat actors to ATT&CK, overlay against detection, produce gap analysis
  • Cloud Migration Planning: Model cloud-specific threats (T1078.004, T1537) and plan detection coverage
  • M&A Security Assessment: Threat model the acquired company's environment against relevant threat actors
  • Budget Justification: Use gap analysis to demonstrate detection blind spots requiring tool investment
  • Purple Team Planning: Select adversary emulation scenarios based on highest-priority gaps from threat model

Output Format

THREAT MODEL ASSESSMENT — Financial Services Division
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Date:             2024-03-15
Threat Actors:    FIN7, APT38, Lazarus Group
Techniques Total: 87 unique techniques across all actors

DETECTION COVERAGE:
  Covered:     56/87 (64%)
  Gaps:        31/87 (36%)

  Tactic Coverage Breakdown:
    Initial Access:      78%  ████████░░
    Execution:           82%  █████████░
    Persistence:         71%  ████████░░
    Priv Escalation:     65%  ███████░░░
    Defense Evasion:     52%  ██████░░░░  <-- Priority gap
    Credential Access:   58%  ██████░░░░  <-- Priority gap
    Discovery:           45%  █████░░░░░
    Lateral Movement:    61%  ███████░░░
    Collection:          50%  ██████░░░░
    Exfiltration:        55%  ██████░░░░
    C2:                  67%  ███████░░░

TOP PRIORITY GAPS (30-day remediation):
  1. T1055 Process Injection — used by all 3 actors, 0 detections
  2. T1003.006 DCSync — used by FIN7 and Lazarus, 0 detections
  3. T1070.004 File Deletion — evidence destruction, 0 detections

INVESTMENT RECOMMENDATION:
  Closing top 10 gaps requires: 2 detection engineer FTEs, 60 days
  Expected coverage improvement: 64% -> 76%

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-threat-modeling-with-mitre-attack of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Threat Modeling With Mitre Attack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Threat Modeling With Mitre Attack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Threat Modeling With Mitre Attack this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Hunt Analytics GenerationOTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
007sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT
Secops Detection Engineeringgoogle/skills21k—~4.8kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT

Similar skills

  • Hunt Analytics Generation

    OTRF/ThreatHunter-Playbook

    Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

    4.7k GitHub stars~819 tokensUpdated 9 mo ago
    SecurityAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed
  • Official

    Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.

    21k GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Threat Modeling With Mitre Attack

What does Implementing Threat Modeling With Mitre Attack do?

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Implementing Threat Modeling With Mitre Attack is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

When should I use Implementing Threat Modeling With Mitre Attack?

Implementing Threat Modeling With Mitre Attack fits situations like: SOC teams need to align detection engineering with threat landscape; conduct threat assessments for new environments; justify security tool procurement.

How do I install Implementing Threat Modeling With Mitre Attack in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-threat-modeling-with-mitre-attack -a claude-code`. Or copy the skill folder (skills/implementing-threat-modeling-with-mitre-attack in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-threat-modeling-with-mitre-attack in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Threat Modeling With Mitre Attack in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-threat-modeling-with-mitre-attack -a codex`. Or copy the skill folder (skills/implementing-threat-modeling-with-mitre-attack in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-threat-modeling-with-mitre-attack in your project. Codex loads it when a task matches its description.

Can I use Implementing Threat Modeling With Mitre Attack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-threat-modeling-with-mitre-attack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-threat-modeling-with-mitre-attack, .gemini/skills/implementing-threat-modeling-with-mitre-attack, .github/skills/implementing-threat-modeling-with-mitre-attack and .opencode/skills/implementing-threat-modeling-with-mitre-attack in your project.

What does Implementing Threat Modeling With Mitre Attack need to run?

Going by SKILL.md and its folder, Implementing Threat Modeling With Mitre Attack needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Threat Modeling With Mitre Attack access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing Threat Modeling With Mitre Attack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Threat Modeling With Mitre Attack use?

Implementing Threat Modeling With Mitre Attack is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Threat Modeling With Mitre Attack use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 566 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Threat Modeling With Mitre Attack?

Skills that share tags, products or a category with Implementing Threat Modeling With Mitre Attack: Hunt Analytics Generation (OTRF/ThreatHunter-Playbook, 4.7k stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars), 007 (sickn33/agentic-awesome-skills, 47k stars) and Secops Detection Engineering (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Threat Modeling With Mitre Attack?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.