proactive-detection▌
24 indexed skills · max 10 per page
detecting-dll-sideloading-attacks
mukul975/Anthropic-Cybersecurity-Skills · detecting-dll-sideloading-attacks
Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.
detecting-process-hollowing-technique
mukul975/Anthropic-Cybersecurity-Skills · detecting-process-hollowing-technique
Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
hunting-for-living-off-the-land-binaries
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-living-off-the-land-binaries
Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
detecting-lateral-movement-with-splunk
mukul975/Anthropic-Cybersecurity-Skills · detecting-lateral-movement-with-splunk
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
detecting-privilege-escalation-attempts
mukul975/Anthropic-Cybersecurity-Skills · detecting-privilege-escalation-attempts
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
hunting-for-living-off-the-cloud-techniques
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-living-off-the-cloud-techniques
Hunt for adversary abuse of legitimate cloud services for C2, data staging, and exfiltration including abuse of Azure, AWS, GCP services, and SaaS platforms.
hunting-for-data-exfiltration-indicators
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-data-exfiltration-indicators
Hunt for data exfiltration through network traffic analysis, detecting unusual data flows, DNS tunneling, cloud storage uploads, and encrypted channel abuse.
hunting-for-command-and-control-beaconing
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-command-and-control-beaconing
Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
detecting-suspicious-powershell-execution
mukul975/Anthropic-Cybersecurity-Skills · detecting-suspicious-powershell-execution
Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.
hunting-for-spearphishing-indicators
mukul975/Anthropic-Cybersecurity-Skills · hunting-for-spearphishing-indicators
Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.