tag
windows-event-logs▌
2 indexed skills · max 10 per page
skills (2)
detecting-rdp-brute-force-attacks
mukul975/Anthropic-Cybersecurity-Skills · detecting-rdp-brute-force-attacks
Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
extracting-windows-event-logs-artifacts
mukul975/Anthropic-Cybersecurity-Skills · extracting-windows-event-logs-artifacts
Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.