Works with the AI tools you already use
Attack Pattern Library Builder
Transform CTI reports into structured attack pattern libraries mapped to MITRE ATT&CK for threat-informed defense.
$15
attack-pattern-library-builder
Example session with this skill installed
Analyze this report excerpt: 'Actor used encoded PowerShell commands to download the stage-2 dropper.' Map it to ATT&CK and provide detection engineering inputs.
- Read your context and instructions
- Compiled the attack-pattern-library-builder
T1059.001 - PowerShell
Confidence: High
Evidence: "Actor used encoded PowerShell commands to download the stage-2 dropper."
Detection Input: Monitor Process_Creation events where parent is cmd.exe and command_line contains '-enc'.
Data Source: Process Command Line, Script Block Logging.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Transform Threat Intelligence into Actionable Defense
The Attack Pattern Library Builder is a specialized skill for security engineers and CTI analysts who need to bridge the gap between raw threat reports and defensive posture. It automates the tedious process of parsing cyber threat intelligence (CTI) to extract specific adversary behaviors, ensuring your defense remains threat-informed and evidence-based.
What it does
- Behavior Extraction: Pulls evidenced procedures from incident reports, advisories, and malware write-ups.
- ATT&CK Mapping: Maps behaviors to specific MITRE ATT&CK techniques with high-fidelity source provenance.
- STIX Structuring: Generates STIX 2.1-inspired attack pattern records for use in TIPs or internal databases.
- Detection Engineering: Translates attacker TTPs into telemetry requirements and detection opportunities.
Why use this skill?
While generic AI might summarize a report, this skill follows strict defensive quality gates. It refuses to "invent" mappings, ensures every technique is tied to a source sentence, and separates tools from procedures. It prevents "hallucinated" security coverage by requiring specific evidence before marking a technique as detected. The result is a professional-grade library that is ready for ingestion into SIEMs, EDRs, or GRC platforms.
Supported Outputs
Produces structured JSON (STIX-style), markdown tables, detection backlogs, and Navigator-compatible layers.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 4 months ago
- Passed all security checks, Safe to install