Files
Anthropic-Cybersecurity-Skills/skills/orchestrating-llm-attacks-with-pyrit/references/standards.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

1.4 KiB

Standards and Framework Mapping — Orchestrating LLM Attacks with PyRIT

MITRE ATLAS (Adversarial Threat Landscape for AI Systems)

ID Name Rationale
AML.T0051 LLM Prompt Injection PyRIT orchestrators inject crafted instructions across conversation turns to make the target act against its intended constraints.
AML.T0054 LLM Jailbreak Crescendo and TAP iteratively defeat safety guardrails; the scorer confirms the moment restrictions are bypassed.

Reference: https://atlas.mitre.org/

NIST AI Risk Management Framework (AI RMF 1.0)

ID Subcategory Rationale
MEASURE-2.7 AI system security and resilience are evaluated and documented PyRIT yields repeatable, scorer-graded measurements of an LLM's resistance to multi-turn adversarial pressure, evidencing this subcategory.

Reference: https://www.nist.gov/itl/ai-risk-management-framework

OWASP Top 10 for LLM Applications (cross-reference)

OWASP ID Risk PyRIT relevance
LLM01:2025 Prompt Injection RedTeaming/Crescendo/TAP orchestrators automate injection.
LLM02:2025 Sensitive Information Disclosure Objective scorers can target data/secret leakage.
LLM07:2025 System Prompt Leakage Objectives can be set to extract the system prompt.

Reference: https://genai.owasp.org/