detecting-living-off-the-land-with-lolbas
mukul975/Anthropic-Cybersecurity-Skills
Guide to detect Living Off the Land Binary misuse via Sysmon/Event Log telemetry, Sigma rules, and parent-child process analysis for certutil, regsvr32, mshta, rundll32, msbuild and siblings, including scoring and structured reporting.