Login
Download
Skill UI
Browse and discover
15857+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
T1003
, found
3
results
Default
Newest
Most Downloaded
Detecting DCSync Attacks in Active Directory
detecting-dcsync-attack-in-active-directory
mukul975/Anthropic-Cybersecurity-Skills
331
This guide details comprehensive detection methods for DCSync attacks (MITRE T1003.006) in Active Directory. Attackers abuse legitimate directory replication protocols to extract sensitive password hashes. Detection relies on auditing Windows Event ID 4662 for unauthorized access attempts to critical Directory Service GUIDs, specifically flagging non-domain-controller accounts attempting replication calls. Essential for threat hunting and incident response.
View Details
Detecting Credential Dumping Activity
detecting-t1003-credential-dumping-with-edr
mukul975/Anthropic-Cybersecurity-Skills
360
A comprehensive guide and set of detection rules for identifying OS credential dumping techniques (MITRE T1003). It leverages EDR telemetry, Sysmon process access monitoring, and Windows security event correlation to detect attacks targeting LSASS memory, SAM databases, and NTDS.dit files. Essential for proactive threat hunting and incident response.
View Details
Detecting DCSync Attacks in Active Directory
hunting-for-dcsync-attacks
mukul975/Anthropic-Cybersecurity-Skills
79
This guide details how to hunt for DCSync attacks (MITRE ATT&CK T1003.006) in Active Directory environments. It focuses on analyzing Windows Security Event ID 4662, specifically looking for DS-Replication-Get-Changes requests originating from non-domain-controller accounts. This technique is critical for incident response, purple teaming, and detecting unauthorized credential theft via Active Directory replication abuse.
View Details
1
Language
简体中文
English