Files
Anthropic-Cybersecurity-Skills/skills/generating-and-analyzing-sboms/references/standards.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

1.4 KiB

Standards and Framework Mapping — Generating and Analyzing SBOMs

NIST Cybersecurity Framework 2.0

ID Name Rationale
ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles SBOMs are the authoritative software-component inventory that underpins lifecycle asset management and supply-chain risk visibility.

MITRE ATT&CK

ID Name Rationale
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools SBOM generation plus vulnerability correlation surfaces vulnerable/compromised dependencies, directly countering this technique.

SBOM Standards and Authorities

Standard / Authority Role
CycloneDX (OWASP) Security-focused SBOM format (VEX, vulnerabilities)
SPDX (ISO/IEC 5962) Licensing/provenance-focused SBOM format
CISA SBOM Minimum Elements Baseline required SBOM fields
US Executive Order 14028 Mandates SBOMs for software sold to the US government
NTIA "Framing Software Component Transparency" Foundational SBOM guidance

Supporting References