Login
Download
Skill UI
Browse and discover
11317+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
Sysmon
, found
4
results
Default
Newest
Most Downloaded
Detecting LOLBAS Abuse Via Process Telemetry
detecting-living-off-the-land-with-lolbas
mukul975/Anthropic-Cybersecurity-Skills
346
This skill provides a comprehensive framework for detecting Living Off the Land Binaries (LOLBAS) abuse, such as misuse of certutil, regsvr32, and mshta. It leverages process telemetry from Sysmon and Windows Event Logs, combined with advanced Sigma rule-based detection and parent-child process anomaly analysis. Ideal for SOC analysts and threat hunters investigating sophisticated adversaries aiming to evade traditional security controls.
View Details
Detecting WMI Event Persistence Artifacts
detecting-wmi-persistence
mukul975/Anthropic-Cybersecurity-Skills
138
This guide details how to detect WMI event subscription persistence, a common attacker technique (T1546.003). It focuses on analyzing suspicious Sysmon Event IDs 19, 20, and 21 to identify malicious EventFilters, EventConsumers, and Bindings. Essential for incident response and threat hunting in Windows environments.
View Details
Hunting Lateral Movement Using WMI Events
hunting-for-lateral-movement-via-wmi
mukul975/Anthropic-Cybersecurity-Skills
477
This skill detects WMI-based lateral movement by analyzing key Windows Security Event ID 4688 and Sysmon Event ID 1 logs. It focuses on identifying suspicious process execution patterns, such as WmiPrvSE.exe spawning unauthorized child processes (cmd.exe, powershell.exe), suspicious command lines, and WMI event subscriptions used for persistence. Ideal for security incident response and threat detection.
View Details
Hunting Process Injection Techniques via Sysmon
hunting-for-process-injection-techniques
mukul975/Anthropic-Cybersecurity-Skills
121
This skill provides a structured methodology for detecting process injection techniques (MITRE ATT&CK T1055), which adversaries use for defense evasion and privilege escalation. It analyzes granular security logs, specifically utilizing Sysmon Event IDs 8 (CreateRemoteThread) and 10 (ProcessAccess), alongside source-target process relationship mapping to identify suspicious malicious behavior over general system activity.
View Details
1
Language
简体中文
English