feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter

Added structured security framework mappings to SKILL.md frontmatter across all applicable skills:
- atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques)
- d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs)
- nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions)

Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
mukul975
2026-04-06 01:56:17 +02:00
parent c15f73db46
commit ef27f026cb
209 changed files with 3959 additions and 3379 deletions
@@ -1,15 +1,31 @@
---
name: performing-lateral-movement-detection
description: >
Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting,
and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and
endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
description: 'Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based
spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK
Lateral Movement (TA0008) techniques.
'
domain: cybersecurity
subdomain: soc-operations
tags: [soc, lateral-movement, mitre-attack, pass-the-hash, psexec, wmi, rdp, smb, detection]
version: "1.0"
tags:
- soc
- lateral-movement
- mitre-attack
- pass-the-hash
- psexec
- wmi
- rdp
- smb
- detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Execution Isolation
- Restore Access
- Application Protocol Command Analysis
- Process Termination
---
# Performing Lateral Movement Detection