Files
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

1.9 KiB

Standards and References — Generating Forensic Timelines with Hayabusa

MITRE ATT&CK References

Technique ID Name Tactic Rationale
T1059.001 Command and Scripting Interpreter: PowerShell Execution Sigma rules over EID 4104/4103/Sysmon flag malicious PowerShell
T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution Process-creation rules surface suspicious cmd usage
T1078 Valid Accounts Defense Evasion / Persistence Logon events (4624/4625/4672) reveal anomalous auth
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Persistence Registry-modification rules flag persistence
T1053.005 Scheduled Task/Job: Scheduled Task Execution / Persistence EID 4698/106 rules surface task creation
T1003 OS Credential Dumping Credential Access Rules flag LSASS access patterns

NIST Cybersecurity Framework 2.0

ID Name Rationale
RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause Hayabusa timelines reconstruct the sequence of events during IR analysis

Detection Standards

Official Resources

Key Research

  • Yamato Security: Hayabusa documentation and AnalysisWithJQ guide
  • Timesketch integration via timesketch-minimal / timesketch-verbose profiles