hunting-for-t1098-account-manipulation
mukul975/Anthropic-Cybersecurity-Skills
This skill guides security analysts through detecting MITRE ATT&CK T1098 account manipulation techniques. It analyzes Windows Security Event Logs (e.g., 4738, 4728) to find signs of unauthorized privilege escalation, group membership changes, or shadow admin account creation. It is essential for proactive threat hunting, incident response, and validating Active Directory security posture.