mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-24 05:30:58 +03:00
feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills
Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions) based on subdomain and content analysis. Restores 11 skills corrupted during prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields. All 754 skills now carry structured mappings for all 5 security frameworks: - MITRE ATT&CK (in tags) - MITRE ATLAS v5.5 (atlas_techniques) - MITRE D3FEND v1.3 (d3fend_techniques) - NIST AI RMF 1.0 (nist_ai_rmf) - NIST CSF 2.0 (nist_csf)
This commit is contained in:
@@ -1,12 +1,24 @@
|
||||
---
|
||||
name: detecting-rdp-brute-force-attacks
|
||||
description: Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
|
||||
description: Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
|
||||
ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
|
||||
domain: cybersecurity
|
||||
subdomain: threat-detection
|
||||
tags: [threat-detection, rdp, brute-force, windows-event-logs, blue-team, siem]
|
||||
version: "1.0"
|
||||
tags:
|
||||
- threat-detection
|
||||
- rdp
|
||||
- brute-force
|
||||
- windows-event-logs
|
||||
- blue-team
|
||||
- siem
|
||||
version: '1.0'
|
||||
author: mahipal
|
||||
license: Apache-2.0
|
||||
nist_csf:
|
||||
- DE.CM-01
|
||||
- DE.AE-02
|
||||
- DE.AE-06
|
||||
- ID.RA-05
|
||||
---
|
||||
# Detecting RDP Brute Force Attacks
|
||||
|
||||
|
||||
Reference in New Issue
Block a user