attack-ent-t1572-protocol-tunneling - Analyze MITRE ATT&CK T1572 Protocol Tunneling
Analyze MITRE ATT&CK T1572 Protocol Tunneling for TTP triage, detection engineering, threat hunting, and defensive emulation planning.
Tags
Updated: 2026-09-17Capabilities
What this skill does
- Clarify analysis scope and assets
- Map user evidence to ATT&CK
- Produce defensive analysis outputs
- Render Markdown defensive brief
Inputs
- User evidence and log sources
- Target platform details
- Bundled reference files
Outputs
- Detection engineering briefs
- Threat hunt plans
- Incident response notes
- ATT&CK coverage assessments
- Rendered Markdown brief file
Requirements
- Python environment
