tag

persistence

20 indexed skills · max 10 per page

skills (20)

hunting-for-webshell-activity

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-webshell-activity

0

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

hunting-for-scheduled-task-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-scheduled-task-persistence

0

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

detecting-wmi-persistence

mukul975/Anthropic-Cybersecurity-Skills · detecting-wmi-persistence

0

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

hunting-for-t1098-account-manipulation

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-t1098-account-manipulation

0

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.

hunting-for-persistence-mechanisms-in-windows

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-mechanisms-in-windows

0

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

conducting-domain-persistence-with-dcsync

mukul975/Anthropic-Cybersecurity-Skills · conducting-domain-persistence-with-dcsync

0

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

analyzing-uefi-bootkit-persistence

mukul975/Anthropic-Cybersecurity-Skills · analyzing-uefi-bootkit-persistence

0

Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing. Activates for requests involving UEFI malware analysis, firmware persistence investigation, boot chain integrity verification, or Secure Boot bypass detection.

hunting-for-suspicious-scheduled-tasks

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-suspicious-scheduled-tasks

0

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.

detecting-malicious-scheduled-tasks-with-sysmon

mukul975/Anthropic-Cybersecurity-Skills · detecting-malicious-scheduled-tasks-with-sysmon

0

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.

hunting-for-startup-folder-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-startup-folder-persistence

0

Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.

prevpage 1 / 2next