tag

threat-hunting

67 indexed skills · max 10 per page

skills (67)

hunting-for-lateral-movement-via-wmi

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-lateral-movement-via-wmi

0

Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.

hunting-for-persistence-via-wmi-subscriptions

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-via-wmi-subscriptions

0

Hunt for adversary persistence through Windows Management Instrumentation event subscriptions by monitoring WMI consumer, filter, and binding creation events that execute malicious code triggered by system events.

detecting-dcsync-attack-in-active-directory

mukul975/Anthropic-Cybersecurity-Skills · detecting-dcsync-attack-in-active-directory

0

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.

hunting-for-unusual-network-connections

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-unusual-network-connections

0

Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.

performing-threat-hunting-with-elastic-siem

mukul975/Anthropic-Cybersecurity-Skills · performing-threat-hunting-with-elastic-siem

0

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

hunting-for-webshell-activity

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-webshell-activity

0

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

hunting-for-anomalous-powershell-execution

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-anomalous-powershell-execution

0

Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events. The analyst parses Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles. Activates for requests involving PowerShell threat hunting, script block analysis, encoded command detection, or AMSI bypass identification.

detecting-service-account-abuse

mukul975/Anthropic-Cybersecurity-Skills · detecting-service-account-abuse

0

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

hunting-for-supply-chain-compromise

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-supply-chain-compromise

0

Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.

detecting-golden-ticket-attacks-in-kerberos-logs

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-attacks-in-kerberos-logs

0

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

prevpage 1 / 7next