mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-24 13:40:57 +03:00
feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills
Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions) based on subdomain and content analysis. Restores 11 skills corrupted during prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields. All 754 skills now carry structured mappings for all 5 security frameworks: - MITRE ATT&CK (in tags) - MITRE ATLAS v5.5 (atlas_techniques) - MITRE D3FEND v1.3 (d3fend_techniques) - NIST AI RMF 1.0 (nist_ai_rmf) - NIST CSF 2.0 (nist_csf)
This commit is contained in:
@@ -1,19 +1,32 @@
|
||||
---
|
||||
name: conducting-memory-forensics-with-volatility
|
||||
description: >
|
||||
Performs memory forensics analysis using Volatility 3 to extract evidence of
|
||||
malware execution, process injection, network connections, and credential theft
|
||||
from RAM dumps captured during incident response. Covers memory acquisition,
|
||||
process analysis, DLL inspection, and malware detection. Activates for requests
|
||||
involving memory forensics, RAM analysis, Volatility framework, memory dump
|
||||
investigation, volatile evidence analysis, or live memory acquisition.
|
||||
description: 'Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
|
||||
network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process
|
||||
analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility
|
||||
framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.
|
||||
|
||||
'
|
||||
domain: cybersecurity
|
||||
subdomain: incident-response
|
||||
tags: [memory-forensics, volatility, RAM-analysis, process-injection, DFIR]
|
||||
mitre_attack: ["T1003", "T1055", "T1620", "T1574"]
|
||||
tags:
|
||||
- memory-forensics
|
||||
- volatility
|
||||
- RAM-analysis
|
||||
- process-injection
|
||||
- DFIR
|
||||
mitre_attack:
|
||||
- T1003
|
||||
- T1055
|
||||
- T1620
|
||||
- T1574
|
||||
version: 1.0.0
|
||||
author: mahipal
|
||||
license: Apache-2.0
|
||||
nist_csf:
|
||||
- RS.MA-01
|
||||
- RS.MA-02
|
||||
- RS.AN-03
|
||||
- RC.RP-01
|
||||
---
|
||||
|
||||
# Conducting Memory Forensics with Volatility
|
||||
|
||||
Reference in New Issue
Block a user