Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
GitHub-Repository

mitre-attack-agent-skills

mitre-attack-agent-skills enthält 918 gesammelte Skills von santosomar, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
918
Stars
24
aktualisiert
2026-05-09
Forks
1
Berufsabdeckung
1 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

attack-mob-t1398-boot-or-logon-initialization-scripts
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1398 Boot or Logon Initialization Scripts in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1398, Boot or Logon Initialization Scripts, or mobile ATT&CK. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.

2026-05-09
attack-mob-t1404-exploitation-for-privilege-escalatio
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1404 Exploitation for Privilege Escalation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1404, Exploitation for Privilege Escalation, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in order to elevate privileges.

2026-05-09
attack-mob-t1406-001-steganography
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1406.001 Steganography in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.001, Steganography, or mobile ATT&CK. Adversaries may use steganography techniques in order to prevent the detection of hidden information.

2026-05-09
attack-mob-t1406-002-software-packing
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1406.002 Software Packing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.002, Software Packing, or mobile ATT&CK. Adversaries may perform software packing to conceal their code.

2026-05-09
attack-mob-t1406-obfuscated-files-or-information
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1406 Obfuscated Files or Information in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406, Obfuscated Files or Information, or mobile ATT&CK. Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.

2026-05-09
attack-mob-t1407-download-new-code-at-runtime
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1407 Download New Code at Runtime in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1407, Download New Code at Runtime, or mobile ATT&CK. Adversaries may download and execute dynamic code not included in the original application package after installation.

2026-05-09
attack-mob-t1409-stored-application-data
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1409 Stored Application Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1409, Stored Application Data, or mobile ATT&CK. Adversaries may try to access and collect application data resident on the device.

2026-05-09
attack-mob-t1414-clipboard-data
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1414 Clipboard Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1414, Clipboard Data, or mobile ATT&CK. Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.

2026-05-09
attack-mob-t1417-001-keylogging
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1417.001 Keylogging in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.001, Keylogging, or mobile ATT&CK. Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.

2026-05-09
attack-mob-t1417-002-gui-input-capture
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1417.002 GUI Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.002, GUI Input Capture, or mobile ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.

2026-05-09
attack-mob-t1417-input-capture
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1417 Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417, Input Capture, or mobile ATT&CK. Adversaries may use methods of capturing user input to obtain credentials or collect information.

2026-05-09
attack-mob-t1418-001-security-software-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1418.001 Security Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418.001, Security Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.

2026-05-09
attack-mob-t1418-software-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1418 Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418, Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of applications that are installed on a device.

2026-05-09
attack-mob-t1420-file-and-directory-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1420 File and Directory Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1420, File and Directory Discovery, or mobile ATT&CK. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.

2026-05-09
attack-mob-t1421-system-network-connections-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1421 System Network Connections Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1421, System Network Connections Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.

2026-05-09
attack-mob-t1422-001-internet-connection-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1422.001 Internet Connection Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.001, Internet Connection Discovery, or mobile ATT&CK. Adversaries may check for Internet connectivity on compromised systems.

2026-05-09
attack-mob-t1422-002-wi-fi-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1422.002 Wi-Fi Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.002, Wi-Fi Discovery, or mobile ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.

2026-05-09
attack-mob-t1422-system-network-configuration-discove
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1422 System Network Configuration Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422, System Network Configuration Discovery, or mobile ATT&CK. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems.

2026-05-09
attack-mob-t1423-network-service-scanning
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1423 Network Service Scanning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1423, Network Service Scanning, or mobile ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.

2026-05-09
attack-mob-t1424-process-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1424 Process Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1424, Process Discovery, or mobile ATT&CK. Adversaries may attempt to get information about running processes on a device.

2026-05-09
attack-mob-t1426-system-information-discovery
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1426 System Information Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1426, System Information Discovery, or mobile ATT&CK. Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.

2026-05-09
attack-mob-t1428-exploitation-of-remote-services
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1428 Exploitation of Remote Services in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1428, Exploitation of Remote Services, or mobile ATT&CK. Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.

2026-05-09
attack-mob-t1429-audio-capture
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1429 Audio Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1429, Audio Capture, or mobile ATT&CK. Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.

2026-05-09
attack-mob-t1430-001-remote-device-management-services
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1430.001 Remote Device Management Services in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.001, Remote Device Management Services, or mobile ATT&CK. An adversary may use access to cloud services (e.g.

2026-05-09
attack-mob-t1430-002-impersonate-ss7-nodes
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1430.002 Impersonate SS7 Nodes in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.002, Impersonate SS7 Nodes, or mobile ATT&CK. Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Securit…

2026-05-09
attack-mob-t1430-location-tracking
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1430 Location Tracking in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430, Location Tracking, or mobile ATT&CK. Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.

2026-05-09
attack-mob-t1437-001-web-protocols
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1437.001 Web Protocols in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437.001, Web Protocols, or mobile ATT&CK. Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.

2026-05-09
attack-mob-t1437-application-layer-protocol
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1437 Application Layer Protocol in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437, Application Layer Protocol, or mobile ATT&CK. Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.

2026-05-09
attack-mob-t1451-sim-card-swap
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1451 SIM Card Swap in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1451, SIM Card Swap, or mobile ATT&CK. Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.(Citation: ATT SIM Swap Scams)(Citation: Verizon SIM Swapping) Th…

2026-05-09
attack-mob-t1453-abuse-accessibility-features
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1453 Abuse Accessibility Features in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1453, Abuse Accessibility Features, or mobile ATT&CK. Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.

2026-05-09
attack-mob-t1456-drive-by-compromise
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1456 Drive-By Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1456, Drive-By Compromise, or mobile ATT&CK. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.

2026-05-09
attack-mob-t1458-replication-through-removable-media
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1458 Replication Through Removable Media in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1458, Replication Through Removable Media, or mobile ATT&CK. Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.

2026-05-09
attack-mob-t1461-lockscreen-bypass
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1461 Lockscreen Bypass in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1461, Lockscreen Bypass, or mobile ATT&CK. An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.

2026-05-09
attack-mob-t1464-network-denial-of-service
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1464 Network Denial of Service in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1464, Network Denial of Service, or mobile ATT&CK. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.

2026-05-09
attack-mob-t1471-data-encrypted-for-impact
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1471 Data Encrypted for Impact in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1471, Data Encrypted for Impact, or mobile ATT&CK. An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.

2026-05-09
attack-mob-t1474-001-compromise-software-dependencies-and
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1474.001 Compromise Software Dependencies and Development Tools in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.001, Compromise Software Dependencies and Development Tools, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

2026-05-09
attack-mob-t1474-002-compromise-hardware-supply-chain
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1474.002 Compromise Hardware Supply Chain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.002, Compromise Hardware Supply Chain, or mobile ATT&CK. Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.

2026-05-09
attack-mob-t1474-003-compromise-software-supply-chain
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1474.003 Compromise Software Supply Chain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.003, Compromise Software Supply Chain, or mobile ATT&CK. Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.

2026-05-09
attack-mob-t1474-supply-chain-compromise
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1474 Supply Chain Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474, Supply Chain Compromise, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

2026-05-09
attack-mob-t1481-001-dead-drop-resolver
Informationssicherheitsanalysten

Analyze MITRE ATT&CK T1481.001 Dead Drop Resolver in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1481.001, Dead Drop Resolver, or mobile ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.

2026-05-09
Zeigt die Top 40 von 918 gesammelten Skills in diesem Repository.