mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-14 20:05:22 +03:00
feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter
Added structured security framework mappings to SKILL.md frontmatter across all applicable skills: - atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques) - d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs) - nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions) Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
@@ -1,17 +1,29 @@
|
||||
---
|
||||
name: detecting-evasion-techniques-in-endpoint-logs
|
||||
description: >
|
||||
Detects defense evasion techniques used by adversaries in endpoint logs including log tampering,
|
||||
timestomping, process injection, and security tool disabling. Use when investigating suspicious
|
||||
endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting
|
||||
for stealthy adversary activity. Activates for requests involving evasion detection, defense
|
||||
evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
|
||||
description: 'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
|
||||
process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection
|
||||
rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving
|
||||
evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.
|
||||
|
||||
'
|
||||
domain: cybersecurity
|
||||
subdomain: endpoint-security
|
||||
tags: [endpoint, edr, threat-hunting, defense-evasion, MITRE-ATT&CK, detection-engineering]
|
||||
tags:
|
||||
- endpoint
|
||||
- edr
|
||||
- threat-hunting
|
||||
- defense-evasion
|
||||
- MITRE-ATT&CK
|
||||
- detection-engineering
|
||||
version: 1.0.0
|
||||
author: mahipal
|
||||
license: Apache-2.0
|
||||
d3fend_techniques:
|
||||
- File Metadata Consistency Validation
|
||||
- Content Format Conversion
|
||||
- File Content Analysis
|
||||
- Platform Hardening
|
||||
- File Format Verification
|
||||
---
|
||||
# Detecting Evasion Techniques in Endpoint Logs
|
||||
|
||||
|
||||
Reference in New Issue
Block a user