feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,17 +1,27 @@
---
name: configuring-windows-event-logging-for-detection
description: >
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security
events for threat detection and forensic investigation. Use when enabling audit policies for
logon events, process creation, privilege use, and object access to feed SIEM detection rules.
Activates for requests involving Windows audit policy, event log configuration, security
logging, or detection-oriented logging.
description: 'Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege
use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration,
security logging, or detection-oriented logging.
'
domain: cybersecurity
subdomain: endpoint-security
tags: [endpoint, windows-security, event-logging, audit-policy, detection-engineering]
tags:
- endpoint
- windows-security
- event-logging
- audit-policy
- detection-engineering
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.PS-02
- DE.CM-01
- PR.IR-01
---
# Configuring Windows Event Logging for Detection