Agent skill

Analysing Attack

by tsale in tsale/awesome-dfir-skills

Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

Apache-2.0Auto-check passedSecurity

Install Analysing Attack

skills CLI
$ npx skills add tsale/awesome-dfir-skills --skill analysing-attack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tsale/awesome-dfir-skills analysing-attack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/analysing-attack-skill .claude/skills/analysing-attack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analysing-attack
GitHub stars
324
Token cost
~1.4k tokens
SKILL.md length
106 words
Files
4
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

  • Performing analysis of threat detections
  • SKILL.md covers Overview and Available Resources
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Cyber threat intelligence

What it does

Analysing Attack is an agent skill from tsale/awesome-dfir-skills. Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `resources/attack_techniques.md` and `resources/attack_version_changelog.md`).

It sits in Security, covering Threat modeling and OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.

When your agent uses it

  • Performing analysis of threat detections
  • Cyber threat intelligence

Example prompts

  • “/analysing-attack”

What it can do on your machine

Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are grep).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analysing Attack loads about 1.4k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 106 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 106 words, ~1,444 tokens.

Download SKILL.mdSave it as .claude/skills/analysing-attack/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analysing-attack
description
Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence

Analysing ATT&CK Tactics and Techniques

Overview

This document provides best practices and resources for use when mapping ATT&CK tactics and techniques to threat detections, threat models, security risks or cyber threat intelligence.

Contains information on v18.1 (latest) version of Mitre ATT&CK

Available Resources

Resources folder contains LLM optimised and token-efficient content. Read whole file for broad context or grep or glob for specfic keywords or IDs. Use index files for quick reference keyword searches.

Tactics are abreviated: REC=Reconnaissance, RD=Resource Development, IA=Initial Access, EX=Execution, PE=Persistence, PRV=Privilege Escalation, DE=Defense Evasion, CA=Credential Access, DIS=Discovery, LM=Lateral Movement, COL=Collection, C2=Command and Control, EXF=Exfiltration, IMP=Impact

Searching Examples

By keyword (recommended for discovery): grep -i "cron\|bash\|/proc/\|cryptocurrency" resources/attack_keywords.idx

By technique ID (for validation): grep "T1053" resources/attack_techniques.md

By tactic abbreviation (find all persistance techniques): grep "PE" resources/attack_techniques.md

Resource Files

ATT&CK Technique Keyword Index: Index file for quick keyword searching to identify suitable ATT&CK IDs for further research. Sorted alphabetically and fomatted as keyword:technique_ids (comma seperated when multiple). See -> resources/attack_keywords.idx

ATT&CK Technique List: Markdown table containing ATT&CK ID, name, keywords, description and platforms. Sorted by ID. Use when researching techniques, valdiating IDs, searching for up-to-date descriptions or filtering by platform. See -> resources/attack_techniques.md

ATT&CK Version Changelog: Reference for v15->v18.1 changes including deprecated techniques, renamed platforms, and the v18 detection model overhaul. Use when analysing older reports or understanding structural changes. See -> resources/attack_version_changelog.md

Best Practice

Use your judgment alongside these guidelines to generate high-quality ATT&CK analysis.

  • Do not assume your knowledge is 100% complete or up to date. Use the resources provided
  • Carefully read any supplied information, perform deep analysis line by line if needed
  • Search broadly for keywords, you may need to iterate multiple times to find every correct technique
  • Think about the specific procedure being performed and consider the attacker (or defender) intent before determining appropriate tactic, technique or sub-technique
  • Some techniques are part of multiple tactics (for ex. T1078 Valid Accounts) and may appear different for each tactic
  • Other techniques are similar but distinct depending on tactic (for ex. T1213.003 and T1593.003 are both Code Respositories)
  • Map to the most specific sub-technique when possible
When Analysing CTI Reports
  • IMPORTANT: Read the whole report fully, including tables of IOCs, appendixes or linked STIX files
  • Screenshots contain valuable intelligence, ensure they are processed
  • Break down the report into granular procedures when mapping to techniques
  • Think about attacker objectives. What did they take that action? What did they hope to achieve?
  • Avoid infering techniques that are not contained in the report
  • Once initial analysis is complete, perform a second analysis to valdiate your findings and idenitify any missed techniques
Show full SKILL.md (217 more words)Show less
When Analysing Detections
  • Detection logic may detect multiple techniques, map all that are applicable
  • Analyse detection log sources and fields, these can help determine distinct tactics or techniques
  • Consider the intent (hypothesis) of the detection, what was the engineers objective?

Commonly Missed Techniques

Command-Line Indicators

-windowstyle hidden|-w hidden -> T1564.003 Hidden Window -encodedcommand|-enc|base64 -> T1027.010 Command Obfuscation -noprofile|-ep bypass -> T1059.001 PowerShell

Encoding

Encoded payload delivered -> T1027.013 Encrypted/Encoded File Decoded at runtime -> T1140 Deobfuscate/Decode

RDP connection|.rdp file -> T1021.001 Remote Desktop Protocol Clipboard redirect -> T1115 Clipboard Data Drive mapping|attached drives -> T1039 Data from Network Shared Drive Auth redirect|intercept -> T1557 Adversary-in-the-Middle

Infrastructure

DDNS|dynamic DNS|No-IP|FreeDNS -> T1568.002 Domain Generation + T1583.006 Web Services Typosquat|lookalike domain -> T1583.001 Domains Compromised server -> T1584.004 Server

Network

SSH tunnel|port forward -> T1572 Protocol Tunneling Downloaded|fetched payload -> T1105 Ingress Tool Transfer Over port 80/443 -> T1071.001 Web Protocols

Social Engineering

Masqueraded|posed as|impersonated -> T1656 Impersonation Spoofed|mimicked|fake page -> T1036.005 Match Legitimate Name Credential harvest|fake login -> T1598.003 Spearphishing Link (Recon)

Technique Pairs

T1566 Spearphishing -> check T1204 User Execution T1027 Obfuscation -> check T1140 Deobfuscation T1053 Scheduled Task -> check T1059 Interpreter T1021.001 RDP -> check T1115, T1039, T1557 T1059.001 PowerShell -> check T1564.003 Hidden Window

Red Flag Phrases

"downloads and executes" -> T1105 + T1059 "persistence via task" -> T1053 + T1059 "C2 over HTTPS" -> T1071.001 + T1573.002 "compromised infrastructure" -> T1584.004 "redirects traffic" -> T1572 or T1090 "harvests credentials via fake page" -> T1598.003 (Recon tactic)

© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/analysis/analysing-attack-skill of tsale/awesome-dfir-skills.

  • SKILL.md
  • resources/attack_keywords.idx
  • resources/attack_techniques.md
  • resources/attack_version_changelog.md

Open the folder on GitHubat commit 6e52942

Compare with similar skills

Analysing Attack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analysing Attack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analysing Attack this skilltsale/awesome-dfir-skills324—~1.4kAutomated safety check: PassApache-2.0
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Performing Reconnaissancetrilwu/secskills156—~3.1kAutomated safety check: NotesMIT
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Recon Osinthypnguyen1209/offensive-claude386—~2.2kAutomated safety check: PassMIT
Wiki ReconEncod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    156 GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    386 GitHub stars~2.2k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Wiki Recon

    Encod3d-Sec/TORCH

    External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

    156 GitHub stars~4.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from tsale/awesome-dfir-skills

  • Malware Analysis

    tsale/awesome-dfir-skills

    Professional malware analysis workflow for PE executables and suspicious files.

    324 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Admiralty System

    tsale/awesome-dfir-skills

    Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

    324 GitHub stars~3.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Osquery Query Helper

    tsale/awesome-dfir-skills

    Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.

    324 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Threat Actor Profiling

    tsale/awesome-dfir-skills

    Build structured threat actor profiles using the 5W1H framework and the Diamond Model.

    324 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Analysing Attack

What does Analysing Attack do?

Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Analysing Attack is an agent skill from tsale/awesome-dfir-skills. Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

When should I use Analysing Attack?

Analysing Attack fits situations like: performing analysis of threat detections; cyber threat intelligence.

How do I install Analysing Attack in Claude Code?

Run `npx skills add tsale/awesome-dfir-skills --skill analysing-attack -a claude-code`. Or copy the skill folder (skills/analysis/analysing-attack-skill in tsale/awesome-dfir-skills) into .claude/skills/analysing-attack in your project. Claude Code loads it when a task matches its description.

How do I install Analysing Attack in Codex?

Run `npx skills add tsale/awesome-dfir-skills --skill analysing-attack -a codex`. Or copy the skill folder (skills/analysis/analysing-attack-skill in tsale/awesome-dfir-skills) into .agents/skills/analysing-attack in your project. Codex loads it when a task matches its description.

Can I use Analysing Attack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill analysing-attack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analysing-attack, .gemini/skills/analysing-attack, .github/skills/analysing-attack and .opencode/skills/analysing-attack in your project.

What does Analysing Attack need to run?

SKILL.md names no scripts, command-line tools or credentials: Analysing Attack is instructions for the agent only.

Does Analysing Attack access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analysing Attack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analysing Attack use?

Analysing Attack is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analysing Attack use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analysing Attack?

Skills that share tags, products or a category with Analysing Attack: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Performing Reconnaissance (trilwu/secskills, 156 stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recon Osint (hypnguyen1209/offensive-claude, 386 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analysing Attack?

tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 324 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.

Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.