feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,19 +1,29 @@
---
name: performing-api-rate-limiting-bypass
description: >
Tests API rate limiting implementations for bypass vulnerabilities by manipulating request
headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent
request throttling controls. The tester identifies rate limit headers, determines enforcement
mechanisms, and attempts bypasses including X-Forwarded-For spoofing, parameter pollution,
case variation, and endpoint path manipulation. Maps to OWASP API4:2023 Unrestricted Resource
Consumption. Activates for requests involving rate limit bypass, API throttling evasion,
brute force protection testing, or API abuse prevention assessment.
description: 'Tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses,
HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit
headers, determines enforcement mechanisms, and attempts bypasses including X-Forwarded-For spoofing, parameter pollution,
case variation, and endpoint path manipulation. Maps to OWASP API4:2023 Unrestricted Resource Consumption. Activates for
requests involving rate limit bypass, API throttling evasion, brute force protection testing, or API abuse prevention assessment.
'
domain: cybersecurity
subdomain: api-security
tags: [api-security, owasp, rate-limiting, throttling, brute-force, dos-prevention]
tags:
- api-security
- owasp
- rate-limiting
- throttling
- brute-force
- dos-prevention
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
---
# Performing API Rate Limiting Bypass