feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,19 +1,29 @@
---
name: performing-api-fuzzing-with-restler
description: >
Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating
and executing test sequences that exercise API endpoints, discover producer-consumer
dependencies between requests, and find security and reliability bugs. The tester compiles
an OpenAPI specification into a RESTler fuzzing grammar, configures authentication, runs
test/fuzz-lean/fuzz modes, and analyzes results for 500 errors, authentication bypasses,
resource leaks, and payload injection vulnerabilities. Activates for requests involving
API fuzzing, RESTler testing, stateful API testing, or automated API security scanning.
description: 'Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences
that exercise API endpoints, discover producer-consumer dependencies between requests, and find security and reliability
bugs. The tester compiles an OpenAPI specification into a RESTler fuzzing grammar, configures authentication, runs test/fuzz-lean/fuzz
modes, and analyzes results for 500 errors, authentication bypasses, resource leaks, and payload injection vulnerabilities.
Activates for requests involving API fuzzing, RESTler testing, stateful API testing, or automated API security scanning.
'
domain: cybersecurity
subdomain: api-security
tags: [api-security, fuzzing, restler, automated-testing, openapi, stateful-testing]
tags:
- api-security
- fuzzing
- restler
- automated-testing
- openapi
- stateful-testing
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
---
# Performing API Fuzzing with RESTler