Attack Tree Construction

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

Instructions onlySecurity
AI-generated overview

Builds attack trees that map attack paths, defense gaps, and security risks for stakeholders.

What it does
This skill guides the construction of attack trees, hierarchical diagrams that break a root attacker goal into sub-goals and atomic attack steps. It defines node types (OR, AND, leaf) and attributes such as cost, time, skill, and detection likelihood, and points to a reference file with templates and worked examples. The output is a structured visualization and analysis of attack scenarios used for defense planning and risk communication.
When to use it
Use it when mapping complex attack scenarios, identifying defense gaps and priorities, or planning penetration tests and security architecture reviews. It is also intended for communicating security risks to stakeholders and justifying defensive investments.
Requirements
No scripts; instructions only. It references a companion file, references/details.md, for templates and worked examples.

Attack Tree Construction

Systematic attack path visualization and analysis.

When to Use This Skill

  • Visualizing complex attack scenarios
  • Identifying defense gaps and priorities
  • Communicating risks to stakeholders
  • Planning defensive investments
  • Penetration test planning
  • Security architecture review

Core Concepts

1. Attack Tree Structure

                    [Root Goal]                         |            ┌────────────┴────────────┐            │                         │       [Sub-goal 1]              [Sub-goal 2]       (OR node)                 (AND node)            │                         │      ┌─────┴─────┐             ┌─────┴─────┐      │           │             │           │   [Attack]   [Attack]      [Attack]   [Attack]    (leaf)     (leaf)        (leaf)     (leaf)

2. Node Types

TypeSymbolDescription
OROvalAny child achieves goal
ANDRectangleAll children required
LeafBoxAtomic attack step

3. Attack Attributes

AttributeDescriptionValues
CostResources needed$, $$, $$$
TimeDuration to executeHours, Days, Weeks
SkillExpertise requiredLow, Medium, High
DetectionLikelihood of detectionLow, Medium, High

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Start with clear goals - Define what attacker wants
  • Be exhaustive - Consider all attack vectors
  • Attribute attacks - Cost, skill, and detection
  • Update regularly - New threats emerge
  • Validate with experts - Red team review

Don'ts

  • Don't oversimplify - Real attacks are complex
  • Don't ignore dependencies - AND nodes matter
  • Don't forget insider threats - Not all attackers are external
  • Don't skip mitigations - Trees are for defense planning
  • Don't make it static - Threat landscape evolves

Source and attribution

Source:wshobson/agentsinplugins/security-scanning/skills/attack-tree-constructionat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal