Claude Skill 04: Map ATT&CK Techniques

Source: Feedly Blog

Author: Josh Darby MacLellan

URL: https://feedly.com/ti-essentials/posts/claude-skill-04-map-att-and-ck-techniques

https://feedly.com/ti-essentials/posts/claude-skill-04-map-att-and-ck-techniques

ONE SENTENCE SUMMARY:

Free Claude Skill maps report-described adversary behaviors to current MITRE ATT&CK techniques, providing evidence, confidence, and Navigator-ready outputs.

MAIN POINTS:

  1. Skill ingests threat reports via paste, file attachment, or URL trigger in Claude.
  2. Workflow starts with recommended defaults or customizable options across up to six questions.
  3. Options include explanation depth, unmapped behaviors, candidate techniques, and output selections.
  4. It checks current ATT&CK version via Version History and attack-stix-data index.
  5. Behaviors map to Enterprise, ICS, or Mobile techniques depending on described activity.
  6. Outputs include Markdown, Word document, and ATT&CK Navigator layers per domain.
  7. Each technique includes quote, location, occurrence status, confidence rating, and rationale.
  8. Script validates quotes against source text and technique IDs against pinned ATT&CK bundle.
  9. Vendor-cited ATT&CK IDs are reconciled as current, revoked, merged, refined, or unsupported.
  10. Optional Feedly MCP integration compares results to Threat Graph profiles and produces comparison layers.

TAKEAWAYS:

  1. Automates CTI “processing” by converting narrative reporting into defensible ATT&CK technique mappings.
  2. Separating occurrence status from confidence reduces ambiguity about evidence versus fit.
  3. Version verification and ID reconciliation help prevent stale or incorrect ATT&CK references.
  4. Navigator layers with quote-backed comments accelerate visualization and stakeholder communication.
  5. Open, editable Skill code enables teams to tailor defaults, naming conventions, and scoring rules.