blue-team▌
2 indexed skills · max 10 per page
detecting-rdp-brute-force-attacks
mukul975/Anthropic-Cybersecurity-Skills · detecting-rdp-brute-force-attacks
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
performing-purple-team-exercise
mukul975/Anthropic-Cybersecurity-Skills · performing-purple-team-exercise
Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.