tag

persistence

20 indexed skills · max 10 per page

skills (20)

langgraph-persistence

langchain-ai/langchain-skills · Productivity

1

Durable graph execution with thread-scoped checkpoints, state history, and cross-thread long-term memory. \n \n Three checkpointer options: InMemorySaver for testing, SqliteSaver for local development, PostgresSaver for production; always pass thread_id in config to enable persistence \n Browse and replay from past checkpoints using get_state_history() , fork execution by updating state at a past point, or manually modify state before resuming \n Store API provides cross-thread memory for user p

hunting-for-webshell-activity

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-webshell-activity

0

Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.

hunting-for-scheduled-task-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-scheduled-task-persistence

0

Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.

detecting-wmi-persistence

mukul975/Anthropic-Cybersecurity-Skills · detecting-wmi-persistence

0

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

hunting-for-t1098-account-manipulation

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-t1098-account-manipulation

0

Hunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.

hunting-for-persistence-mechanisms-in-windows

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-persistence-mechanisms-in-windows

0

Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.

conducting-domain-persistence-with-dcsync

mukul975/Anthropic-Cybersecurity-Skills · conducting-domain-persistence-with-dcsync

0

Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting KRBTGT, Domain Admin, and service account hashes for Golden Ticket creation.

analyzing-uefi-bootkit-persistence

mukul975/Anthropic-Cybersecurity-Skills · analyzing-uefi-bootkit-persistence

0

Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing. Activates for requests involving UEFI malware analysis, firmware persistence investigation, boot chain integrity verification, or Secure Boot bypass detection.

hunting-for-suspicious-scheduled-tasks

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-suspicious-scheduled-tasks

0

Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.

detecting-malicious-scheduled-tasks-with-sysmon

mukul975/Anthropic-Cybersecurity-Skills · detecting-malicious-scheduled-tasks-with-sysmon

0

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes, public directory paths, and encoded command arguments to identify persistence and lateral movement via scheduled tasks. Activates for requests involving scheduled task detection, Sysmon persistence hunting, or T1053.005 Scheduled Task/Job analysis.

prevpage 1 / 2next