event-correlation▌
3 indexed skills · max 10 per page
performing-timeline-reconstruction-with-plaso
mukul975/Anthropic-Cybersecurity-Skills · performing-timeline-reconstruction-with-plaso
Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.
detecting-ntlm-relay-with-event-correlation
mukul975/Anthropic-Cybersecurity-Skills · detecting-ntlm-relay-with-event-correlation
Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis.
performing-log-analysis-for-forensic-investigation
mukul975/Anthropic-Cybersecurity-Skills · performing-log-analysis-for-forensic-investigation
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.