feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,18 +1,29 @@
---
name: hunting-for-anomalous-powershell-execution
description: >
Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104),
Module Logging (Event 4103), and process creation events. The analyst parses Windows
Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded
payloads, credential dumping keywords, and suspicious download cradles. Activates for
requests involving PowerShell threat hunting, script block analysis, encoded command
detection, or AMSI bypass identification.
description: 'Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event
4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI
bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests
involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification.
'
domain: cybersecurity
subdomain: threat-hunting
tags: [powershell, script-block-logging, event-4104, amsi, threat-hunting, evtx, obfuscation]
version: "1.0"
tags:
- powershell
- script-block-logging
- event-4104
- amsi
- threat-hunting
- evtx
- obfuscation
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
---
# Hunting for Anomalous PowerShell Execution