hunting-for-dcom-lateral-movement
mukul975/Anthropic-Cybersecurity-Skills
This skill provides comprehensive detection strategies for adversaries abusing DCOM objects (e.g., MMC20.Application) to perform stealthy lateral movement (MITRE ATT&CK T1021.003). It details how to correlate Sysmon Event IDs (Process Creation, Network Connection), analyze WMI activity, and monitor RPC traffic on port 135 to identify unauthorized remote command execution chains. Ideal for advanced threat hunting, red teaming, and purple team exercises.