feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,18 +1,28 @@
---
name: implementing-attack-surface-management
description: >
Implements external attack surface management (EASM) using Shodan, Censys, and
ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain
enumeration, service fingerprinting, and exposure scoring. Includes a weighted
risk scoring algorithm based on OWASP attack surface analysis methodology and
the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM
programs or performing external reconnaissance for security assessments.
description: 'Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder,
httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted
risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ).
Use when building continuous ASM programs or performing external reconnaissance for security assessments.
'
domain: cybersecurity
subdomain: offensive-security
tags: [attack-surface, reconnaissance, shodan, censys, subfinder, nuclei, asset-discovery]
version: "1.0"
tags:
- attack-surface
- reconnaissance
- shodan
- censys
- subfinder
- nuclei
- asset-discovery
version: '1.0'
author: mukul975
license: Apache-2.0
nist_csf:
- ID.RA-01
- GV.OV-02
- DE.AE-07
---
# Implementing Attack Surface Management