tag

threat-hunting

67 indexed skills · max 10 per page

skills (67)

hunting-for-command-and-control-beaconing

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-command-and-control-beaconing

0

Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.

detecting-suspicious-powershell-execution

mukul975/Anthropic-Cybersecurity-Skills · detecting-suspicious-powershell-execution

0

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

detecting-t1003-credential-dumping-with-edr

mukul975/Anthropic-Cybersecurity-Skills · detecting-t1003-credential-dumping-with-edr

0

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

hunting-for-dns-based-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-dns-based-persistence

0

Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.

detecting-ntlm-relay-with-event-correlation

mukul975/Anthropic-Cybersecurity-Skills · detecting-ntlm-relay-with-event-correlation

0

Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis.

hunting-for-spearphishing-indicators

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-spearphishing-indicators

0

Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.

hunting-for-registry-persistence-mechanisms

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-registry-persistence-mechanisms

0

Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.

hunting-for-shadow-copy-deletion

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-shadow-copy-deletion

0

Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands.

detecting-email-forwarding-rules-attack

mukul975/Anthropic-Cybersecurity-Skills · detecting-email-forwarding-rules-attack

0

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.

hunting-for-lolbins-execution-in-endpoint-logs

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-lolbins-execution-in-endpoint-logs

0

Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes.

prevpage 6 / 7next