tag

lateral-movement

20 indexed skills · max 10 per page

skills (20)

conducting-internal-network-penetration-test

mukul975/Anthropic-Cybersecurity-Skills · conducting-internal-network-penetration-test

0

Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.

hunting-for-dcom-lateral-movement

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-dcom-lateral-movement

0

Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects through Sysmon Event ID 1 (process creation) and Event ID 3 (network connection) correlation, WMI event analysis, RPC endpoint mapper traffic on port 135, and DCOM-specific parent-child process relationships.

detecting-lateral-movement-with-splunk

mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-with-splunk

0

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.

detecting-azure-lateral-movement

mukul975/Anthropic-Cybersecurity-Skills · detecting-azure-lateral-movement

0

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.

performing-deception-technology-deployment

mukul975/Anthropic-Cybersecurity-Skills · performing-deception-technology-deployment

0

Deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.

configuring-microsegmentation-for-zero-trust

mukul975/Anthropic-Cybersecurity-Skills · configuring-microsegmentation-for-zero-trust

0

Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.

detecting-attacks-on-historian-servers

mukul975/Anthropic-Cybersecurity-Skills · detecting-attacks-on-historian-servers

0

Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.

performing-lateral-movement-with-wmiexec

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-with-wmiexec

0

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.

implementing-network-segmentation-with-firewall-zones

mukul975/Anthropic-Cybersecurity-Skills · implementing-network-segmentation-with-firewall-zones

0

Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.

containing-active-breach

mukul975/Anthropic-Cybersecurity-Skills · containing-active-breach

0

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.

prevpage 2 / 2next