Works with the AI tools you already use
Apt Group Mitre Navigator Analysis
Transform APT threat intelligence into MITRE ATT&CK Navigator layers and prioritized detection gap analyses.
$10
apt-group-mitre-navigator-analysis
Example session with this skill installed
Analyse APT29 using MITRE ATT&CK Enterprise. Produce a Navigator layer specification and a detection gap analysis. I have attached our SIEM use case register as the coverage evidence source. Focus on Windows and identity platforms.
- Read your context and instructions
- Compiled the apt-group-mitre-navigator-analysis
The skill confirms the ATT&CK domain and platform scope, produces an APT29 group profile summary with aliases and ATT&CK group ID, maps all documented techniques to tactics and sub-techniques, generates a Navigator layer specification in structured JSON-ready format with colour coding for covered, partially covered, and gap techniques, classifies detection coverage from the supplied SIEM use case register only, produces a gap register for uncovered high-priority techniques, and outputs a prioritised detection engineering backlog with data source requirements for each gap technique. All unconfirmed coverage is marked as unknown, and analyst validation questions are included for ambiguous mappings.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill transforms threat intelligence into actionable cyber defense strategies. It analyzes APT groups, campaigns, and TTP sets to generate MITRE ATT&CK Navigator layers, detection gap analyses, and prioritized engineering backlogs. By mapping actor behavior against your specific security stack, it identifies exactly where your monitoring is blind and where it is robust.
Why use this skill
Unlike basic LLM prompting, this skill follows a strict defensive methodology to ensure accuracy and appliance neutrality. It prevents "hallucinated coverage" by requiring evidence before marking a technique as detected. It bridges the gap between raw threat intel and SOC operations by producing machine-readable Navigator JSON and human-readable risk summaries, ensuring your detection engineering team focuses on the highest-probability threats.
Supported Analysis & Outputs
- ATT&CK Navigator Integration: Generates and validates functional JSON layer specifications for visualization.
- Gap Analysis: Compares actor techniques against EDR, SIEM, and NDR rule sets to find coverage holes.
- Detection Prioritization: Ranks techniques based on actor usage, data source feasibility, and environment relevance.
- Threat Profiling: Summarizes intrusion sets and campaigns with precise technique-to-tactic mapping.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 4 months ago
- Passed all security checks, Safe to install