What problem does it solve? Detection engineers often mislabel threat intelligence with wrong ATT&CK technique IDs, over-tag detection rules, or use revoked techniques, producing unreliable coverage claims. This Skill enforces disciplined ATT&CK mapping across OpenTide TVM, DOM, and MDR objects. ## Core Features & Use Cases - Mapping Discipline: Decision rules for choosing tactic vs technique vs sub-technique, correct tactic assignment by adversary intent, and multi-technique chaining with independent evidence per step. - Version & Revocation Handling: Guidance for ATT&CK v19 (including the Defense Evasion split into Stealth TA0005 and Defense Impairment TA0112), version pinning, and replacing revoked technique IDs. - Coverage Gap Analysis: Inverse mapping from detection rules to the ATT&CK matrix with Detected/Hunted/Theoretical/Gap classification and anti-pattern detection. - Use Case: When writing a detection rule for LSASS memory dumping, use this Skill to map it precisely to T1003.001, validate the data components your platform collects, and confirm the technique applies to your target platform. ## Quick Start Use the mitre-attack skill to map this threat intelligence report to the correct ATT&CK techniques and check our detection coverage gaps.