Skip to content
Back to skills

Att&Ck

ASecurity

Exhaustively test each MITRE ATT&CK technique.

  • 86 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 10, 2026
securityshelltestinggit

Works with

  • terminal

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 10, 2026

npx -y skills add 0dayInc/pwn --skill 'att&ck' --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Att&Ck?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Att&Ck
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/0dayinc-att-ck/badge)](https://www.skillsdirectory.com/skills/0dayinc-att-ck)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "att&ck"
description: "Exhaustively test each MITRE ATT&CK technique."
license: MIT
allowed-tools: [pwn, terminal, extrospection]
metadata:
  bundled: true
  references:
    - https://attack.mitre.org/
    - https://github.com/mitre-attack/attack-stix-data
    - ATT&CK 19.2
---

# ATT&CK exhaustive testing

Use when the ask names a technique (T1059, T1059.001), a tactic (TA0002),
ATT&CK coverage, purple-team emulation, or "test this like an adversary".
Pair with `capec` (how the attack is performed) and `cwe` (weakness proved).

## When to use

- "T1190", "OS Credential Dumping", "coverage of persistence"
- Red / purple team playbooks keyed to ATT&CK
- Mapping detections to techniques

## Methodologies

| Catalog | Role |
|---|---|
| ATT&CK 19.2 | techniques, sub-techniques, tactics (Enterprise / Mobile / ICS) |
| CAPEC (bundled `capec` skill) | attack-pattern execution for mapped IDs |
| CWE (bundled `cwe` skill) | weakness IDs after the procedure succeeds |
| NIST SP 800-115 | technical assessment wrapper |

## How to look up a technique

Each ATT&CK ID is a file in this skill:

```text
references/<id>.md
```

Examples: `references/T1059.md`, `references/T1059.001.md`,
`references/TA0006.md`. Open the file and follow it end-to-end.
`references/INDEX.md` lists every ID.

## Exhaustive catalog procedure

1. Identify platforms in scope (Windows, Linux, SaaS, ICS, Android, …).
2. Pick tactics in scope (or the whole matrix).
3. For every **applicable** technique, run `references/<id>.md`.
4. When sub-techniques exist, the parent is incomplete until every child is done.
5. Record N/A with a reason when the platform does not exist.
6. Findings cite the technique ID, not only the tactic.
7. Re-read saved evidence before calling the technique tested.

## Tooling

- Always: `skills_recall` this skill, then read the technique file.
- Then: `capec` and `cwe` for mapped IDs.
- Host: `pwn_eval`, shell, `PWN::Plugins::PS`.
- HTTP: `PWN::Plugins::BurpSuite` / `TransparentBrowser`.
- Network: `PWN::Plugins::Packet`.

## Pitfalls

- Tactics are groupings; they are not techniques.
- Atomic Tests / scanner mappings are inventory until you execute and save evidence.
- Skipping sub-techniques is not parent coverage.
- Detection engineering without an emulation attempt is not a test.

## Verification

A technique is done when its reference checklist is ticked and evidence
was re-read. Matrix coverage is done when every applicable technique
in the chosen tactics is tested or N/A.

## Catalog size (ATT&CK 19.2)

- Techniques / sub-techniques: 1166
- Tactics: 41

Full table: `references/INDEX.md`.

Files in this skill

  • SKILL.md2.6 KB
  • references/INDEX.md74.3 KB
  • references/T0800.md3.5 KB
  • references/T0801.md3.1 KB
  • references/T0802.md3.3 KB
  • references/T0803.md3.5 KB
  • references/T0804.md3.8 KB
  • references/T0805.md4.2 KB
  • references/T0806.md3.7 KB
  • references/T0807.md3.7 KB
  • references/T0808.md3.3 KB
  • references/T0809.md3.8 KB
  • references/T0810.md4 KB
  • references/T0811.md4 KB
  • references/T0812.md3.6 KB
  • references/T0813.md3.6 KB
  • references/T0814.md4.6 KB
  • references/T0815.md3.6 KB
  • references/T0816.md3.7 KB
  • references/T0817.md4.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…