Login
Download
Skill UI
Browse and discover
15857+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
Events
, found
320
results
Default
Newest
Most Downloaded
EDR Credential Dumping Detection
detecting-credential-dumping-with-edr
mukul975/Anthropic-Cybersecurity-Skills
318
Provides analysts with a workflow to hunt and investigate credential dumping (LSASS, SAM, NTDS, DCSync) using EDR telemetry, Sysmon access events, and AD replication monitoring.
View Details
Detecting Compromised Email Accounts
detecting-email-account-compromise
mukul975/Anthropic-Cybersecurity-Skills
493
A comprehensive guide and analysis framework for detecting compromised Office 365 or Google Workspace email accounts. It focuses on analyzing unified audit logs and Azure AD sign-in logs to identify indicators of account takeover (ATO) or Business Email Compromise (BEC). Detection methods include monitoring impossible travel events, identifying malicious inbox rules (e.g., external forwarding or deletion rules), and analyzing suspicious Microsoft Graph API access patterns.
View Details
Detecting Malicious Scheduled Tasks with Sysmon
detecting-malicious-scheduled-tasks-with-sysmon
mukul975/Anthropic-Cybersecurity-Skills
144
This skill provides a structured methodology for detecting persistence and lateral movement via malicious scheduled tasks. It utilizes Sysmon Event IDs (1, 11) and Windows Security Events (4698/4702) to correlate process creation, task file writes, and task registration details. Ideal for threat hunting and building robust detection rules for T1053.005.
View Details
Detect RDP Brute Force Attacks
detecting-rdp-brute-force-attacks
mukul975/Anthropic-Cybersecurity-Skills
232
This skill provides a structured method for analyzing Windows Security Event Logs (EVTX) to detect brute force attacks targeting RDP endpoints. It involves parsing failed logon events (Event ID 4625) and correlating them with successful logons (Event ID 4624), while also analyzing source IP frequency and NLA bypass attempts. Ideal for security incident investigation, blue-team threat hunting, and building SIEM detection rules.
View Details
Detecting Elevation Abuse and Privilege Escalation
detecting-t1548-abuse-elevation-control-mechanism
mukul975/Anthropic-Cybersecurity-Skills
463
A comprehensive guide for threat hunting, detailing detection methods for the abuse of elevation controls (T1548). It covers both Windows environments (UAC bypass via registry modification and auto-elevating binaries like fodhelper.exe) and Linux systems (sudo/setuid abuse). Use this to monitor system events, registry changes, and process relationships to identify unauthorized privilege escalation attempts.
View Details
Detecting WMI Persistence Subscriptions
detecting-wmi-persistence
mukul975/Anthropic-Cybersecurity-Skills
292
A comprehensive guide for threat hunters and incident responders to detect WMI-based persistence mechanisms (MITRE T1546.003). It details the analysis of Sysmon Event IDs 19, 20, and 21, cross-referencing these events with root\subscription namespaces and using tools like Autoruns and SIEM analysis for robust detection.
View Details
Hunting Anomalous PowerShell Execution
hunting-for-anomalous-powershell-execution
mukul975/Anthropic-Cybersecurity-Skills
63
A comprehensive tool for security analysts to hunt for malicious PowerShell activity. It analyzes Windows Event Log (EVTX) files by parsing Script Block Logging (Event 4104), Module Logging (4103), and process creation events. Detects obfuscated commands, AMSI bypass attempts, encoded payloads, and credential dumping techniques crucial for incident response and threat hunting.
View Details
Detecting WMI Lateral Movement Activity
hunting-for-lateral-movement-via-wmi
mukul975/Anthropic-Cybersecurity-Skills
87
This tool analyzes Windows Event Logs (ID 4688, Sysmon ID 1) and WMI-Activity Operational events to detect suspicious lateral movement. It specifically hunts for WmiPrvSE.exe spawning child processes (like cmd.exe or powershell.exe) or identifying WMI event subscriptions, which are common indicators of remote code execution and persistence.
View Details
Hunting Scheduled Task Persistence Techniques
hunting-for-scheduled-task-persistence
mukul975/Anthropic-Cybersecurity-Skills
282
A comprehensive guide for hypothesis-driven threat hunting focusing on Windows Scheduled Task persistence (T1053). This methodology guides the creation of advanced SIEM/EDR queries against critical events like task creation (Event ID 4698), suspicious actions, and unusual scheduling patterns. Essential for incident response, proactive threat hunting, and security assessments.
View Details
Detect Suspicious Windows Service Installations
hunting-for-unusual-service-installations
mukul975/Anthropic-Cybersecurity-Skills
295
This skill performs threat hunting for persistence mechanisms by parsing Windows System event logs (Event ID 7045). It specifically detects suspicious service installations, analyzing service binary paths, and correlating these events with advanced telemetry (Sysmon/EDR) to identify indicators of compromise (MITRE ATT&CK T1543.003). Ideal for incident response and security validation.
View Details
LOLBAS Detection Rules
hunting-living-off-the-land-binaries
mukul975/Anthropic-Cybersecurity-Skills
103
Monitors Windows process creation events to flag Living Off The Land Binary abuse by matching Event ID 4688/Sysmon 1 logs against LOLBAS database entries, supporting threat hunting and SIEM rule creation for fileless attacks.
View Details
Enforcing API Schema Validation Security
implementing-api-schema-validation-security
mukul975/Anthropic-Cybersecurity-Skills
366
This solution enforces strict data contract validation for all APIs using OpenAPI Specification (OAS) and JSON Schema. It ensures that all incoming requests and outgoing responses conform to predefined structures. By implementing validation at both the API Gateway (runtime) and during development (shift-left), it effectively prevents critical security vulnerabilities such as SQL injection, XSS, unauthorized data leakage, and mass assignment.
View Details
Prev
1
2
3
...
7
8
9
10
11
12
13
...
25
26
27
Next
Language
简体中文
English