feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter

Added structured security framework mappings to SKILL.md frontmatter across all applicable skills:
- atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques)
- d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs)
- nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions)

Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
mukul975
2026-04-06 01:56:17 +02:00
parent c15f73db46
commit ef27f026cb
209 changed files with 3959 additions and 3379 deletions
@@ -1,17 +1,30 @@
---
name: detecting-anomalous-authentication-patterns
description: >
Detects anomalous authentication patterns using UEBA analytics, statistical baselines,
and machine learning models to identify impossible travel, credential stuffing, brute force,
password spraying, and compromised account behaviors across authentication logs.
Activates for requests involving authentication anomaly detection, login behavior analysis,
description: 'Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
models to identify impossible travel, credential stuffing, brute force, password spraying, and compromised account behaviors
across authentication logs. Activates for requests involving authentication anomaly detection, login behavior analysis,
UEBA implementation, or suspicious sign-in investigation.
'
domain: cybersecurity
subdomain: identity-access-management
tags: [UEBA, authentication-anomaly, impossible-travel, brute-force, credential-stuffing, behavioral-analytics]
version: "1.0"
tags:
- UEBA
- authentication-anomaly
- impossible-travel
- brute-force
- credential-stuffing
- behavioral-analytics
version: '1.0'
author: mahipal
license: Apache-2.0
atlas_techniques:
- AML.T0043
- AML.T0018
nist_ai_rmf:
- MEASURE-2.7
- MEASURE-2.5
- MAP-5.1
---
# Detecting Anomalous Authentication Patterns