mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-24 05:30:58 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# Standards and Frameworks Reference
|
||||
|
||||
## Applicable Standards
|
||||
- **STIX 2.1**: Structured Threat Information eXpression for CTI data representation
|
||||
- **TAXII 2.1**: Transport protocol for sharing CTI over HTTPS
|
||||
- **MITRE ATT&CK**: Adversary tactics, techniques, and procedures taxonomy
|
||||
- **Diamond Model**: Intrusion analysis framework (Adversary, Capability, Infrastructure, Victim)
|
||||
- **Traffic Light Protocol (TLP)**: Information sharing classification (CLEAR, GREEN, AMBER, RED)
|
||||
|
||||
## MITRE ATT&CK Relevance
|
||||
- Technique mapping for threat actor behavior classification
|
||||
- Data sources for detection capability assessment
|
||||
- Mitigation strategies linked to specific techniques
|
||||
|
||||
## Industry Frameworks
|
||||
- NIST Cybersecurity Framework (CSF) 2.0 - Identify function
|
||||
- ISO 27001:2022 - A.5.7 Threat Intelligence
|
||||
- FIRST Standards - TLP, CSIRT, vulnerability coordination
|
||||
|
||||
## References
|
||||
- [STIX 2.1 Specification](https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html)
|
||||
- [MITRE ATT&CK](https://attack.mitre.org/)
|
||||
- [Diamond Model Paper](https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf)
|
||||
- [NIST CSF 2.0](https://www.nist.gov/cyberframework)
|
||||
@@ -0,0 +1,31 @@
|
||||
# Indicator Lifecycle Management Workflows
|
||||
|
||||
## Workflow 1: Collection and Analysis
|
||||
```
|
||||
[Intelligence Sources] --> [Data Collection] --> [Analysis] --> [Reporting]
|
||||
| | | |
|
||||
v v v v
|
||||
OSINT/HUMINT/SIGINT Normalize/Enrich Assess/Correlate Disseminate
|
||||
```
|
||||
|
||||
### Steps:
|
||||
1. **Planning**: Define intelligence requirements and collection priorities
|
||||
2. **Collection**: Gather data from relevant sources
|
||||
3. **Processing**: Normalize data formats and filter noise
|
||||
4. **Analysis**: Apply analytical frameworks and correlate findings
|
||||
5. **Production**: Generate intelligence products and reports
|
||||
6. **Dissemination**: Share with stakeholders via appropriate channels
|
||||
7. **Feedback**: Collect consumer feedback to refine future collection
|
||||
|
||||
## Workflow 2: Continuous Monitoring
|
||||
```
|
||||
[Watchlist] --> [Automated Monitoring] --> [Change Detection] --> [Alert/Update]
|
||||
```
|
||||
|
||||
### Steps:
|
||||
1. **Define Watchlist**: Identify indicators, actors, and topics to monitor
|
||||
2. **Configure Monitoring**: Set up automated collection from relevant sources
|
||||
3. **Change Detection**: Identify new or changed intelligence
|
||||
4. **Assessment**: Evaluate significance of changes
|
||||
5. **Alerting**: Notify stakeholders of significant intelligence updates
|
||||
6. **Archive**: Store intelligence for historical analysis and trending
|
||||
Reference in New Issue
Block a user