LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: mitre-attack

Browse skills that share this tag.

  • implementing-continuous-security-validation-with-bas - Implementing Continuous Security Validation with BAS
    breach-attack-simulationbassecurity-validationsafebreach

    ★ 8 · Updated 2026-09-22

    Deploy Breach and Attack Simulation tools to continuously validate security control effectiveness by safely emulating real-world attack techniques.

    ⚙ Deploy BAS platform components⚙ Configure attack scenarios⚙ Map results to security controls
  • performing-dark-web-monitoring-for-threats - Perform dark web monitoring to identify threats
    threat-intelligencedark-webtorcti

    ★ 17 · Updated 2026-09-22

    Systematically scans Tor hidden services, paste sites, and ransomware leak sites to identify leaked credentials and threats targeting organizations.

    ⚙ Set up Tor HTTP client⚙ Verify Tor proxy connection⚙ Monitor paste sites for credential leaks
  • attack-ent-t1572-protocol-tunneling - Analyze MITRE ATT&CK T1572 Protocol Tunneling
    enterprisecommand-and-controlT1572protocol-tunneling

    ★ 29 · Updated 2026-09-17

    Analyze MITRE ATT&CK T1572 Protocol Tunneling for TTP triage, detection engineering, threat hunting, and defensive emulation planning.

    ⚙ Clarify analysis scope and assets⚙ Map user evidence to ATT&CK⚙ Produce defensive analysis outputs
  • executing-red-team-engagement-planning - Executing Red Team Engagement Planning
    red-teamadversary-simulationmitre-attackexploitation

    ★ 1 · Updated 2026-09-17

    Defines scope, objectives, rules of engagement, threat models, and timelines before offensive security testing.

    ⚙ Define engagement scope and objectives⚙ Establish rules of engagement⚙ Select adversary threat profiles
  • attack-ent-t1218-012-verclsid - Analyze MITRE ATT&CK T1218.012 Verclsid Technique
    mitre-attackenterpriset1218-012verclsid

    ★ 29 · Updated 2026-09-16

    Analyze MITRE ATT&CK T1218.012 Verclsid technique for TTP triage, detection engineering, threat hunting, and defensive planning.

    ⚙ Analyze T1218.012 technique context⚙ Map user evidence to ATT&CK⚙ Generate detection and hunt guidance
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunt for adversary abuse of signed system binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.

    ⚙ Define hunt hypotheses⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntinglolbinsdefense-evasionedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • red-team-tactics - Adversary simulation principles based on MITRE ATT&CK.
    red-teammitre-attackcybersecurityadversary-simulation

    ★ 1 · Updated 2026-09-14

    Provides principles, attack phases, evasion techniques, and reporting guidance for red team adversary simulation based on MITRE ATT&CK.

    ⚙ Simulate MITRE ATT&CK attack phases⚙ Map target attack surfaces⚙ Escalate system privileges
  • red-team-tactics - Red team tactics principles based on MITRE ATT&CK
    red-teammitre-attackadversary-simulationsecurity

    ★ 0 · Updated 2026-09-14

    Provides red team adversary simulation principles, attack lifecycle phases, defense evasion, and reporting guidelines.

    ⚙ Map attack surface⚙ Gain initial access⚙ Execute target code
  • writing-a-malware-analysis-report - Writing a Malware Analysis Report
    malwarereportingiocmitre-attack

    ★ 22 · Updated 2026-09-13

    Structures malware analysis reports covering summary, sample identity, capabilities, IOCs, ATT&CK mapping, and detection guidance.

    ⚙ Write executive summary⚙ Record sample identity⚙ Describe malware capabilities
  • detecting-insider-threat-behaviors - Detecting Insider Threat Behaviors
    threat-huntingmitre-attackinsider-threatdata-theft

    ★ 2 · Updated 2026-09-12

    Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and data theft.

    ⚙ Formulate detection hypotheses⚙ Identify required data sources⚙ Execute detection queries
  • detecting-mimikatz-execution-patterns - Detecting Mimikatz Execution Patterns
    threat-huntingmitre-attackmimikatzcredential-dumping

    ★ 4 · Updated 2026-09-12

    Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

    ⚙ Formulate detection hypothesis⚙ Identify log data sources⚙ Execute SIEM EDR detection queries
  • T1550.001_application-access-token - Use stolen application access tokens for authentication bypass
    mitre-attackenterprisedefense-evasionlateral-movement

    ★ 2,684 · Updated 2026-05-28

    Use stolen application access tokens to bypass authentication and access restricted accounts, information, or services.

    ⚙ steal application access tokens⚙ bypass authentication process⚙ access restricted accounts
  • T1566.001_spearphishing-attachment - Spearphishing Attachment Initial Access
    initial-accessphishingmitre-attackT1566.001

    ★ 2,684 · Updated 2026-05-09

    Send spearphishing emails with malicious attachments to gain system access

    ⚙ Send spearphishing emails⚙ Attach malicious files⚙ Exploit vulnerabilities
  • conducting-full-scope-red-team-engagement - Execute MITRE ATT&CK Red Team Engagement
    red-teamadversary-emulationmitre-attackpenetration-testing

    ★ 3,613 · Updated 2026-03-24

    Execute red team engagement from reconnaissance to post-exploitation using MITRE ATT&CK-aligned tactics

    ⚙ execute red team engagement⚙ perform reconnaissance⚙ gain initial access