mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-06 19:00:17 +03:00
feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter
Added structured security framework mappings to SKILL.md frontmatter across all applicable skills: - atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques) - d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs) - nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions) Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
@@ -1,16 +1,38 @@
|
||||
---
|
||||
name: implementing-siem-use-cases-for-detection
|
||||
description: >
|
||||
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and
|
||||
behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.
|
||||
Use when SOC teams need to expand detection coverage, formalize use case lifecycle management,
|
||||
or build a detection library aligned to organizational threat profile.
|
||||
description: 'Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics
|
||||
mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage,
|
||||
formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.
|
||||
|
||||
'
|
||||
domain: cybersecurity
|
||||
subdomain: soc-operations
|
||||
tags: [soc, siem, use-cases, detection-engineering, mitre-attack, splunk, elastic, sentinel]
|
||||
version: "1.0"
|
||||
tags:
|
||||
- soc
|
||||
- siem
|
||||
- use-cases
|
||||
- detection-engineering
|
||||
- mitre-attack
|
||||
- splunk
|
||||
- elastic
|
||||
- sentinel
|
||||
version: '1.0'
|
||||
author: mahipal
|
||||
license: Apache-2.0
|
||||
nist_ai_rmf:
|
||||
- MEASURE-2.7
|
||||
- MAP-5.1
|
||||
- MANAGE-2.4
|
||||
atlas_techniques:
|
||||
- AML.T0070
|
||||
- AML.T0066
|
||||
- AML.T0082
|
||||
d3fend_techniques:
|
||||
- Token Binding
|
||||
- Restore Access
|
||||
- Password Authentication
|
||||
- Reissue Credential
|
||||
- Strong Password Policy
|
||||
---
|
||||
# Implementing SIEM Use Cases for Detection
|
||||
|
||||
|
||||
Reference in New Issue
Block a user