feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,16 +1,29 @@
---
name: investigating-insider-threat-indicators
description: >
Investigates insider threat indicators including data exfiltration attempts, unauthorized access
patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and
HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous
data movement by employees, or need to build investigation timelines for potential insider threats.
description: 'Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy
violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive
insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines
for potential insider threats.
'
domain: cybersecurity
subdomain: soc-operations
tags: [soc, insider-threat, data-exfiltration, dlp, ueba, investigation, hr-correlation]
version: "1.0"
tags:
- soc
- insider-threat
- data-exfiltration
- dlp
- ueba
- investigation
- hr-correlation
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06
---
# Investigating Insider Threat Indicators