tag

windows-security

10 indexed skills · max 10 per page

skills (10)

detecting-pass-the-ticket-attacks

mukul975/Anthropic-Cybersecurity-Skills · detecting-pass-the-ticket-attacks

0

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

configuring-windows-defender-advanced-settings

mukul975/Anthropic-Cybersecurity-Skills · configuring-windows-defender-advanced-settings

0

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. Use when hardening Windows endpoints beyond default Defender settings, deploying enterprise-grade endpoint protection, or meeting compliance requirements for advanced malware defense. Activates for requests involving Windows Defender configuration, ASR rules, MDE tuning, or Microsoft endpoint security.

detecting-t1548-abuse-elevation-control-mechanism

mukul975/Anthropic-Cybersecurity-Skills · detecting-t1548-abuse-elevation-control-mechanism

0

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.

implementing-application-whitelisting-with-applocker

mukul975/Anthropic-Cybersecurity-Skills · implementing-application-whitelisting-with-applocker

0

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. Use when enforcing application control policies, meeting compliance requirements for software restriction, or preventing execution of unsigned or untrusted binaries. Activates for requests involving AppLocker, application whitelisting, software restriction, or executable control.

detecting-credential-dumping-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-credential-dumping-techniques

0

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

detecting-malicious-scheduled-tasks-with-sysmon

mukul975/Anthropic-Cybersecurity-Skills · detecting-malicious-scheduled-tasks-with-sysmon

0

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.

implementing-disk-encryption-with-bitlocker

mukul975/Anthropic-Cybersecurity-Skills · implementing-disk-encryption-with-bitlocker

0

Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection.

configuring-windows-event-logging-for-detection

mukul975/Anthropic-Cybersecurity-Skills · configuring-windows-event-logging-for-detection

0

Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation. Use when enabling audit policies for logon events, process creation, privilege use, and object access to feed SIEM detection rules. Activates for requests involving Windows audit policy, event log configuration, security logging, or detection-oriented logging.

detecting-golden-ticket-forgery

mukul975/Anthropic-Cybersecurity-Skills · detecting-golden-ticket-forgery

0

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM

hardening-windows-endpoint-with-cis-benchmark

mukul975/Anthropic-Cybersecurity-Skills · hardening-windows-endpoint-with-cis-benchmark

0

Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, remediating audit findings, or establishing organization-wide security baselines. Activates for requests involving Windows hardening, CIS benchmarks, GPO security baselines, or endpoint configuration compliance.