building-attack-pattern-library-from-cti-reports
mukul975/Anthropic-Cybersecurity-Skills
This skill parses various cyber threat intelligence (CTI) reports (Mandiant, CrowdStrike, etc.) using NLP and specialized libraries (stix2, mitreattack-python, spaCy). It systematically extracts adversary behaviors, maps them to MITRE ATT&CK IDs, and constructs a searchable STIX 2.1 Attack Pattern library. This is essential for threat-informed detection engineering, generating detection rules (Sigma, YARA), and validating security controls.