Files
Anthropic-Cybersecurity-Skills/skills/operationalizing-misp-threat-feeds/references/standards.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

1.5 KiB

Standards and Framework Mapping

MITRE ATT&CK

ID Name Rationale
T1589 Gather Victim Identity Information Feeds catalog adversary reconnaissance/identity indicators; operationalizing them detects and contextualizes such activity.
T1071.001 Application Layer Protocol: Web Protocols C2 domain/URL IOCs become Suricata/Sigma web detections.
T1071.004 Application Layer Protocol: DNS Malicious-domain IOCs drive DNS-based Wazuh/Suricata detection.
T1105 Ingress Tool Transfer File-hash IOCs detect known malicious payload delivery.

NIST Cybersecurity Framework 2.0

ID Name Rationale
ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources MISP feed curation, caching, and operationalization is the direct implementation of receiving and applying shared cyber threat intelligence.

Supporting Standards and References

  • Traffic Light Protocol (TLP 2.0). Governs how ingested/shared intelligence may be redistributed; enforced via MISP taxonomies.
  • STIX 2.1 / TAXII 2.1. Interoperable representation/transport of CTI that MISP can import/export.
  • NIST SP 800-150 — Guide to Cyber Threat Information Sharing. Frames the feed-ingestion and sharing lifecycle this skill operationalizes.
  • SigmaHQ specification. Detection rule format generated from MISP attributes.
  • MISP automation & REST return formats: https://www.circl.lu/doc/misp/automation/
  • PyMISP documentation: https://pymisp.readthedocs.io/