mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-28 12:19:41 +03:00
feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter
Added structured security framework mappings to SKILL.md frontmatter across all applicable skills: - atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques) - d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs) - nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions) Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
@@ -1,19 +1,26 @@
|
||||
---
|
||||
name: detecting-pass-the-ticket-attacks
|
||||
description: Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM
|
||||
description: Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
|
||||
ticket usage patterns in Splunk and Elastic SIEM
|
||||
domain: cybersecurity
|
||||
subdomain: threat-detection
|
||||
tags:
|
||||
- kerberos
|
||||
- pass-the-ticket
|
||||
- active-directory
|
||||
- splunk
|
||||
- elastic
|
||||
- credential-theft
|
||||
- windows-security
|
||||
version: "1.0"
|
||||
- kerberos
|
||||
- pass-the-ticket
|
||||
- active-directory
|
||||
- splunk
|
||||
- elastic
|
||||
- credential-theft
|
||||
- windows-security
|
||||
version: '1.0'
|
||||
author: mahipal
|
||||
license: Apache-2.0
|
||||
d3fend_techniques:
|
||||
- Token Binding
|
||||
- Execution Isolation
|
||||
- Restore Access
|
||||
- Application Protocol Command Analysis
|
||||
- Process Termination
|
||||
---
|
||||
|
||||
# Detecting Pass-the-Ticket Attacks
|
||||
|
||||
Reference in New Issue
Block a user