Attack Tree Construction

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

僅含說明Security
AI 產生的概覽

建構攻擊樹,用來梳理攻擊路徑、防禦缺口與安全風險並向相關方溝通。

功能
此技能指導建構攻擊樹,也就是把攻擊者的根目標逐層拆解為子目標與原子攻擊步驟的階層圖。它定義了節點類型(OR、AND、葉節點)以及成本、時間、技能、被偵測可能性等屬性,並指向一個含有範本與完整範例的參考檔案。產出是用於防禦規劃與風險溝通的結構化攻擊情境視覺化與分析。
適用情境
適用於梳理複雜攻擊情境、找出防禦缺口與優先順序,或規劃滲透測試與安全架構審查。也用於向相關方溝通安全風險並論證防禦投資。
執行需求
不需要指令碼,僅為說明性內容。它引用配套檔案 references/details.md 以取得範本與完整範例。

Attack Tree Construction

Systematic attack path visualization and analysis.

When to Use This Skill

  • Visualizing complex attack scenarios
  • Identifying defense gaps and priorities
  • Communicating risks to stakeholders
  • Planning defensive investments
  • Penetration test planning
  • Security architecture review

Core Concepts

1. Attack Tree Structure

                    [Root Goal]                         |            ┌────────────┴────────────┐            │                         │       [Sub-goal 1]              [Sub-goal 2]       (OR node)                 (AND node)            │                         │      ┌─────┴─────┐             ┌─────┴─────┐      │           │             │           │   [Attack]   [Attack]      [Attack]   [Attack]    (leaf)     (leaf)        (leaf)     (leaf)

2. Node Types

TypeSymbolDescription
OROvalAny child achieves goal
ANDRectangleAll children required
LeafBoxAtomic attack step

3. Attack Attributes

AttributeDescriptionValues
CostResources needed$, $$, $$$
TimeDuration to executeHours, Days, Weeks
SkillExpertise requiredLow, Medium, High
DetectionLikelihood of detectionLow, Medium, High

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Start with clear goals - Define what attacker wants
  • Be exhaustive - Consider all attack vectors
  • Attribute attacks - Cost, skill, and detection
  • Update regularly - New threats emerge
  • Validate with experts - Red team review

Don'ts

  • Don't oversimplify - Real attacks are complex
  • Don't ignore dependencies - AND nodes matter
  • Don't forget insider threats - Not all attackers are external
  • Don't skip mitigations - Trees are for defense planning
  • Don't make it static - Threat landscape evolves

來源與署名

來源:wshobson/agents位於plugins/security-scanning/skills/attack-tree-construction提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架