performing-lateral-movement-detection
mukul975/Anthropic-Cybersecurity-Skills
Detects lateral movement such as Pass-the-Hash, PsExec, WMI, RDP, and SMB spreading by correlating Windows logs, NetFlow/Zeek data, and endpoint telemetry mapped to ATT&CK TA0008, supporting SOC investigations and detection engineering.