mukul975
768ca51c8d
chore: bump plugin version to v1.3.0
2026-06-22 17:11:46 +00:00
mukul975
101ca0bd88
chore: auto-update index.json and skill count
2026-06-22 17:08:43 +00:00
mukul975
8cae0648ec
Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
...
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):
- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
invocation, guardrails, model/data poisoning, system-prompt leakage,
embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration
Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00
mukul975
13a1c4afd9
chore: auto-update index.json and skill count
2026-06-22 11:17:20 +00:00
mukul975
51140175a3
Fix plugin version (1.0.0->1.2.0), sync skill count to 762, automate both
...
- plugin.json was stuck at version 1.0.0 and count 753 — this is the file the
installer reads, so installs showed 1.0 everywhere. Bumped to 1.2.0 / 762.
- Update skill count to 762 across README (badge + 6 mentions), marketplace.json,
and plugin.json (754/753 -> 762 after merging PRs #70/#71/#81)
- update-index.yml: now auto-syncs the skill count into README.md,
marketplace.json, and plugin.json on every skills/ change (no more manual drift)
- sync-marketplace-version.yml: release now bumps plugin.json too (not just
marketplace.json) and pushes to main, so plugin version tracks the release tag
2026-06-22 13:16:56 +02:00
mukul975
7eebca88aa
chore: auto-update index.json
2026-06-20 14:44:31 +00:00
mukul975
8f0f3f2b60
chore: auto-update index.json
2026-06-20 14:44:17 +00:00
mukul975
3f82a6f962
chore: auto-update index.json
2026-06-20 14:44:06 +00:00
mukul975
da758bf053
chore: auto-update index.json
2026-06-20 14:43:55 +00:00
mukul975
7d7c6342eb
Add MITRE F3 badge to README badge cluster and bump frameworks count to 6
2026-06-20 16:27:18 +02:00
mukul975
9f9217875f
chore: auto-update index.json
2026-06-20 14:06:27 +00:00
mukul975
886658219f
Add MITRE Fight Fraud Framework (F3 v1.1) mappings to fraud-relevant skills
...
- Add mitre_f3 frontmatter block to 94 fraud-relevant skills (phishing,
account takeover, banking malware, BEC, identity/KYC, payment/card fraud,
money-mule/cash-out, ransomware extortion, DFIR, threat intel)
- Map each skill to F3 v1.1 tactics + precise technique IDs, including the
two F3-specific tactics ATT&CK lacks: Positioning (FA0001) and
Monetization (FA0002)
- All 123 F3 v1.1 technique IDs validated against the upstream STIX bundle
(github.com/center-for-threat-informed-defense/fight-fraud-framework):
0 invalid IDs, 0 invalid tactics, 0 name mismatches, no placeholder IDs
- mitre_f3 kept as a separate block from mitre_attack (F3 redefines several
ATT&CK tactics for the fraud context)
- Add docs/mitre-f3-mapping.md schema reference
- Update README: F3 as the 6th framework, dedicated F3 section + badge
2026-06-20 16:06:04 +02:00
mukul975
04450304b1
chore: auto-update index.json
2026-06-01 10:15:47 +00:00
mukul975
cb8d79e068
Map all 754 skills to MITRE ATT&CK v19.1
...
- Add validated mitre_attack frontmatter to all 754 skills (286 distinct
techniques), verified against MITRE ATT&CK v19.1 via the official
mitreattack-python library: 0 revoked, deprecated, or invalid IDs
- Curate precise per-skill technique IDs for forensics, malware-analysis,
threat-intel, and red-team skills (e.g. DCSync -> T1003.006,
Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003)
- Reconcile v19.1 tactic restructuring: Defense Evasion split into
Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.*
family and T1070.001/.002 remapped to active equivalents (T1685.*)
- Normalize word-split tags across 35 skills (remove filename-derived
stopword tags, add semantic cybersecurity tags)
- Add api-reference.md for 3 skills that were missing it
- Update README ATT&CK section with accurate v19.1 tactic distribution
2026-06-01 12:13:29 +02:00
mukul975
9a588e643e
chore: auto-update index.json
2026-05-30 09:32:08 +00:00
mukul975
77d5d9d686
chore: auto-update index.json
2026-04-26 12:03:37 +00:00
mukul975
4ae0be7f48
chore: bump marketplace version to v1.2.0
2026-04-06 12:26:39 +02:00
mukul975
dcc2dc32fd
fix: jq command line continuation in sync-marketplace workflow
2026-04-06 12:25:16 +02:00
mukul975
c0ab6cfccb
docs: update README for v1.2.0 — 5-framework coverage, 754 skills
2026-04-06 12:06:22 +02:00
mukul975
b4231b19e7
chore: auto-update index.json
2026-04-06 09:17:52 +00:00
mukul975
efca3ec611
feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills
...
Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.
All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
2026-04-06 11:17:40 +02:00
mukul975
e8105a2f4d
chore: auto-update index.json
2026-04-05 23:56:33 +00:00
mukul975
ef27f026cb
feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter
...
Added structured security framework mappings to SKILL.md frontmatter across all applicable skills:
- atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques)
- d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs)
- nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions)
Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
2026-04-06 01:56:17 +02:00
mukul975
c15f73db46
chore: auto-update index.json
2026-04-03 06:56:09 +00:00
mukul975
6325c202c5
chore: auto-update index.json
2026-04-03 06:30:32 +00:00
mukul975
7283f02ba9
chore: auto-update index.json
2026-03-28 11:41:02 +00:00
mukul975
476a0880f4
Fix ESET AV false positive on AMSI bypass strings in skill docs
2026-03-28 12:40:53 +01:00
mukul975
0fbcbdf8dd
chore: auto-update index.json
2026-03-27 09:24:27 +00:00
mukul975
9314565dd9
docs: update release version from v1.0.0 to v1.1.0 in README
2026-03-23 19:17:24 +01:00
mukul975
c74a7547bb
docs: replace static contributors table with contrib.rocks auto-updating widget
2026-03-23 19:16:03 +01:00
mukul975
f4e791c06c
docs: remove fake contributor Systech2021-1952 from README
2026-03-23 19:14:33 +01:00
mukul975
577f795252
docs: update skill count to 753 and domain count to 38 across all files
2026-03-21 13:57:15 +01:00
mukul975
ac77250450
docs: use single name Mahipal in CITATION.cff
2026-03-21 13:38:37 +01:00
mukul975
57b684e4d6
docs: add CITATION.cff for academic and tool attribution
2026-03-21 13:37:55 +01:00
mukul975
3856835990
chore: auto-update index.json
2026-03-21 12:23:42 +00:00
mukul975
db3eaaeaf2
fix: add workflow_dispatch and self-trigger to update-index workflow
2026-03-21 13:23:34 +01:00
mukul975
7f60276fd9
fix: add missing import re in update-index workflow, bump version to 1.1.0
2026-03-21 13:21:55 +01:00
mukul975
e2c3836c30
feat: upgrade 5 skills with full content for v1.1.0
...
Replaced stub SKILL.md files with complete implementations:
- analyzing-linux-audit-logs-for-intrusion (257 lines, full auditd workflow)
- analyzing-windows-amcache-artifacts (237 lines, AmcacheParser + timeline)
- detecting-oauth-token-theft (266 lines, Azure AD token protection)
- implementing-devsecops-security-scanning (372 lines, full CI/CD pipeline)
- implementing-privileged-session-monitoring (323 lines, PAM session audit)
Also bumps index.json to version 1.1.0.
2026-03-21 12:36:58 +01:00
mukul975
d77aaf8b28
Fix index.json: restore description field for skill registration
2026-03-21 11:46:09 +01:00
mukul975
777b3b97a2
Update contact email to mukuljangra5@gmail.com
2026-03-21 11:43:18 +01:00
mukul975
38915dec6d
Slim index.json to name+path only, fix plugin domain loading
...
- index.json: 463KB -> 84KB (name+path only, single cybersecurity domain)
- update-index.yml: generates compact slim index on every push
- marketplace.json + plugin.json: update skill count 607+ to 753
2026-03-21 11:39:28 +01:00