Attack Tree Construction

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

仅含说明Security
AI 生成的概览

构建攻击树,用于梳理攻击路径、防御缺口与安全风险并传达给相关方。

功能
该技能指导构建攻击树,即把攻击者的根目标逐层拆解为子目标和原子攻击步骤的层级图。它定义了节点类型(OR、AND、叶子)以及成本、时间、技能、被检测可能性等属性,并指向一个包含模板和完整示例的参考文件。产出是用于防御规划和风险沟通的结构化攻击场景可视化与分析。
适用场景
适用于梳理复杂攻击场景、识别防御缺口与优先级,或规划渗透测试和安全架构评审。也用于向相关方传达安全风险并论证防御投入。
运行要求
无需脚本,仅为说明性内容。它引用配套文件 references/details.md 以获取模板和完整示例。

Attack Tree Construction

Systematic attack path visualization and analysis.

When to Use This Skill

  • Visualizing complex attack scenarios
  • Identifying defense gaps and priorities
  • Communicating risks to stakeholders
  • Planning defensive investments
  • Penetration test planning
  • Security architecture review

Core Concepts

1. Attack Tree Structure

                    [Root Goal]                         |            ┌────────────┴────────────┐            │                         │       [Sub-goal 1]              [Sub-goal 2]       (OR node)                 (AND node)            │                         │      ┌─────┴─────┐             ┌─────┴─────┐      │           │             │           │   [Attack]   [Attack]      [Attack]   [Attack]    (leaf)     (leaf)        (leaf)     (leaf)

2. Node Types

TypeSymbolDescription
OROvalAny child achieves goal
ANDRectangleAll children required
LeafBoxAtomic attack step

3. Attack Attributes

AttributeDescriptionValues
CostResources needed$, $$, $$$
TimeDuration to executeHours, Days, Weeks
SkillExpertise requiredLow, Medium, High
DetectionLikelihood of detectionLow, Medium, High

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Start with clear goals - Define what attacker wants
  • Be exhaustive - Consider all attack vectors
  • Attribute attacks - Cost, skill, and detection
  • Update regularly - New threats emerge
  • Validate with experts - Red team review

Don'ts

  • Don't oversimplify - Real attacks are complex
  • Don't ignore dependencies - AND nodes matter
  • Don't forget insider threats - Not all attackers are external
  • Don't skip mitigations - Trees are for defense planning
  • Don't make it static - Threat landscape evolves

来源与署名

来源:wshobson/agents位于plugins/security-scanning/skills/attack-tree-construction提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架