Map all 754 skills to MITRE ATT&CK v19.1

- Add validated mitre_attack frontmatter to all 754 skills (286 distinct
  techniques), verified against MITRE ATT&CK v19.1 via the official
  mitreattack-python library: 0 revoked, deprecated, or invalid IDs
- Curate precise per-skill technique IDs for forensics, malware-analysis,
  threat-intel, and red-team skills (e.g. DCSync -> T1003.006,
  Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003)
- Reconcile v19.1 tactic restructuring: Defense Evasion split into
  Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.*
  family and T1070.001/.002 remapped to active equivalents (T1685.*)
- Normalize word-split tags across 35 skills (remove filename-derived
  stopword tags, add semantic cybersecurity tags)
- Add api-reference.md for 3 skills that were missing it
- Update README ATT&CK section with accurate v19.1 tactic distribution
This commit is contained in:
mukul975
2026-06-01 12:13:29 +02:00
parent 9a588e643e
commit cb8d79e068
755 changed files with 7832 additions and 2286 deletions
@@ -1,10 +1,12 @@
---
name: exploiting-excessive-data-exposure-in-api
description: 'Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying
on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal
identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps
to OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving API data leakage testing,
excessive data exposure, response filtering bypass, or API over-fetching.
description: 'Tests APIs for excessive data exposure where endpoints return more data
than the client application needs, relying on the frontend to filter sensitive fields.
The tester intercepts API responses and analyzes them for leaked PII, internal identifiers,
debug information, or sensitive business data that the UI does not display but the
API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization.
Activates for requests involving API data leakage testing, excessive data exposure,
response filtering bypass, or API over-fetching.
'
domain: cybersecurity
@@ -23,6 +25,12 @@ nist_csf:
- ID.RA-01
- PR.DS-10
- DE.CM-01
mitre_attack:
- T1190
- T1059.007
- T1552.001
- T1027
- T1070
---
# Exploiting Excessive Data Exposure in API