tag

proactive-detection

24 indexed skills · max 10 per page

skills (24)

hunting-for-unusual-network-connections

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-unusual-network-connections

0

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

hunting-for-webshell-activity

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-webshell-activity

0

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

detecting-service-account-abuse

mukul975/Anthropic-Cybersecurity-Skills · detecting-service-account-abuse

0

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

hunting-for-supply-chain-compromise

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-supply-chain-compromise

0

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

hunting-for-scheduled-task-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-scheduled-task-persistence

0

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

detecting-pass-the-hash-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-pass-the-hash-attacks

0

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

detecting-mimikatz-execution-patterns

mukul975/Anthropic-Cybersecurity-Skills · detecting-mimikatz-execution-patterns

0

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

building-threat-hunt-hypothesis-framework

mukul975/Anthropic-Cybersecurity-Skills · building-threat-hunt-hypothesis-framework

0

Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.

detecting-kerberoasting-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-kerberoasting-attacks

0

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.

hunting-for-persistence-mechanisms-in-windows

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-mechanisms-in-windows

0

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

prevpage 1 / 3next