Files
Anthropic-Cybersecurity-Skills/skills/validating-tpm-measured-boot-attestation/references/standards.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

26 lines
1.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Standards and Framework Mapping
## MITRE ATT&CK
| ID | Name | Rationale |
|----|------|-----------|
| T1542 | Pre-OS Boot | Measured boot detects the pre-OS tampering this technique relies on. |
| T1542.001 | Pre-OS Boot: System Firmware | PCR 07 drift reveals unauthorized firmware modification. |
| T1542.003 | Pre-OS Boot: Bootkit | Bootloader/kernel measurements (PCR 810) expose bootkit changes. |
| T1014 | Rootkit | Quote verification and IMA measurements surface concealed tampering. |
| T1601.001 | Modify System Image: Patch System Image | Attestation against golden values flags unauthorized image patches. |
## NIST Cybersecurity Framework 2.0
| ID | Name | Rationale |
|----|------|-----------|
| PR.PS-01 | Configuration management practices are established and applied | Measured-boot baselining and attestation enforce and verify the approved firmware/kernel configuration of platforms. |
## Supporting Standards and References
- **TCG TPM 2.0 Library Specification.** Defines PCRs, extend semantics, quotes, and attestation keys.
- **TCG PC Client Platform Firmware Profile.** Assigns PCR index meanings (PCR 07 firmware, PCR 7 Secure Boot, PCR 810 OS/IMA).
- **RFC 9683 — Remote Integrity Verification of Network Devices Containing TPMs.** Standardizes TPM-based remote attestation.
- **NIST SP 800-155 — BIOS Integrity Measurement Guidelines.** Measured-boot and integrity reporting guidance.
- **NSA UEFI/Boot Security guidance.** Recommends measured boot + attestation alongside Secure Boot.