feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,17 +1,29 @@
---
name: triaging-security-alerts-in-splunk
description: >
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating
notable events, correlating related telemetry, and making escalation or closure decisions using
SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from
correlation searches, need to prioritize investigation order, or must document triage decisions
for handoff to Tier 2/3 analysts.
description: 'Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events,
correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard.
Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document
triage decisions for handoff to Tier 2/3 analysts.
'
domain: cybersecurity
subdomain: soc-operations
tags: [soc, splunk, alert-triage, siem, notable-events, correlation-search, incident-review]
version: "1.0"
tags:
- soc
- splunk
- alert-triage
- siem
- notable-events
- correlation-search
- incident-review
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06
---
# Triaging Security Alerts in Splunk