Login
Download
Skill UI
Browse and discover
11170+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
tor
, found
3385
results
Default
Newest
Most Downloaded
Detecting Data Staging Before Exfiltration
hunting-for-data-staging-before-exfiltration
mukul975/Anthropic-Cybersecurity-Skills
425
This skill guides security analysts in detecting data staging activities, a critical precursor to data exfiltration. It monitors for the use of archiving tools (7-Zip, RAR), unusual file consolidation patterns, and suspicious writes to temporary or hidden directories using EDR and process telemetry. Essential for proactive threat hunting and improving detection coverage for T1074 techniques.
View Details
Detecting DCSync Attacks Via Event Logs
hunting-for-dcsync-attacks
mukul975/Anthropic-Cybersecurity-Skills
338
This guide details how to hunt for DCSync attacks, a technique used to steal password hashes from Active Directory. It involves analyzing Windows Event ID 4662 to identify unauthorized DS-Replication-Get-Changes requests originating from non-domain-controller accounts. Essential for incident response and threat detection.
View Details
Hunting for DNS-Based Persistence Mechanisms
hunting-for-dns-based-persistence
mukul975/Anthropic-Cybersecurity-Skills
103
This skill guides security analysts through advanced threat-hunting methodologies focused on detecting DNS-based persistence. It analyzes passive DNS history, zone file audits, and API data (like SecurityTrails) to identify unauthorized record modifications, subdomain takeovers, and DNS hijacking attempts that bypass traditional security controls. Ideal for SOC analysts and threat hunters.
View Details
Detecting DNS Tunneling and Data Exfiltration
hunting-for-dns-tunneling-with-zeek
mukul975/Anthropic-Cybersecurity-Skills
250
A comprehensive guide and detection methodology for identifying covert communication channels utilizing DNS records. This technique analyzes Zeek dns.log for indicators such as high-entropy subdomains, excessive query volume, unusually long query lengths, and abnormal record type distributions, which suggest data exfiltration or Command and Control (C2) activity.
View Details
Hunting for NTLM Relay Attacks Detection
hunting-for-ntlm-relay-attacks
mukul975/Anthropic-Cybersecurity-Skills
389
This skill provides advanced threat hunting capabilities to detect NTLM relay attacks within Active Directory environments. It analyzes critical Windows Security Event 4624 logs, specifically focusing on logon type 3 using NTLMSSP authentication. The detection logic identifies suspicious patterns, including IP-to-hostname mismatches, rapid multi-host authentications, and lack of SMB signing enforcement, helping SOC analysts pinpoint unauthorized credential access attempts.
View Details
Detect WMI Persistence Via Event Subscriptions
hunting-for-persistence-via-wmi-subscriptions
mukul975/Anthropic-Cybersecurity-Skills
115
This guide details advanced threat hunting techniques to proactively uncover adversary persistence mechanisms leveraging Windows Management Instrumentation (WMI) event subscriptions. It monitors the creation and binding of WMI events (Filter, Consumer, Binding) to detect malicious, fileless backdoors used by sophisticated threat actors, especially when standard persistence locations are clean.
View Details
Hunting Registry Persistence Mechanisms In Windows
hunting-for-registry-persistence-mechanisms
mukul975/Anthropic-Cybersecurity-Skills
461
A detailed methodology for proactive threat hunting focused on identifying deep-seated persistence mechanisms within Windows operating systems. This guide covers advanced techniques such as monitoring Run keys, analyzing Winlogon modifications, detecting IFEO injection, and identifying COM object hijacking. It is crucial for incident response, purple teaming, and ensuring system integrity against advanced persistent threats (APTs).
View Details
Detecting Registry Run Key Persistence
hunting-for-registry-run-key-persistence
mukul975/Anthropic-Cybersecurity-Skills
430
This guide details a threat hunting technique for detecting persistence mechanisms utilizing Windows Registry Run keys (T1547.001). By analyzing Sysmon Event ID 13 logs, it identifies suspicious auto-start entries pointing to temporary directories, encoded PowerShell commands, or abused LOLBins. Essential for SOC analysts and security engineers investigating incidents and developing robust detection rules.
View Details
Hunting Shadow Copy Deletion Activity
hunting-for-shadow-copy-deletion
mukul975/Anthropic-Cybersecurity-Skills
424
This methodology guides security professionals in proactively hunting for suspicious activity related to Volume Shadow Copy deletion. By monitoring commands like vssadmin, wmic, and PowerShell usage, it helps detect anti-forensics techniques and preparatory steps often executed by ransomware actors, crucial during incident response or threat hunting exercises.
View Details
Hunting For Spearphishing Indicators Detection
hunting-for-spearphishing-indicators
mukul975/Anthropic-Cybersecurity-Skills
443
This guide details a structured threat hunting methodology designed to proactively detect sophisticated spearphishing campaigns. It instructs users on correlating indicators across email logs, endpoint telemetry (EDR), and network data (SIEM) to identify targeted threats, supporting incident response and security posture improvement.
View Details
Hunting Startup Folder Persistence Mechanisms
hunting-for-startup-folder-persistence
mukul975/Anthropic-Cybersecurity-Skills
247
Detects persistence mechanisms (T1547.001) by monitoring critical Windows startup directories. This skill analyzes autoruns entries, monitors for real-time file system changes using Python watchdog, and examines file metadata (like creation timestamps and digital signatures) to identify suspicious implants and unauthorized execution points.
View Details
Hunting For Supply Chain Compromise Indicators
hunting-for-supply-chain-compromise
mukul975/Anthropic-Cybersecurity-Skills
487
This guide details proactive threat hunting techniques focused on detecting supply chain compromises. Use it when investigating trojanized software updates, compromised dependencies (npm/PyPI), or tampered build artifacts. It outlines a structured workflow using EDR/SIEM data (CrowdStrike, Splunk) to identify hidden threats and scope the impact of sophisticated attacks.
View Details
Prev
1
2
3
...
134
135
136
137
138
139
140
...
281
282
283
Next
Language
简体中文
English