detecting-service-account-abuse
mukul975/Anthropic-Cybersecurity-Skills
This skill provides a framework for proactively detecting service account abuse, which often occurs through anomalous interactive logons, privilege escalation, or lateral movement. It leverages EDR/SIEM telemetry (e.g., CrowdStrike, Splunk) and advanced threat intelligence rules (Sigma) to identify compromised accounts performing unexpected activities. Ideal for incident response, threat hunting, and security posture assessment.