tag

wmi

5 indexed skills · max 10 per page

skills (5)

hunting-for-lateral-movement-via-wmi

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-lateral-movement-via-wmi

0

Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.

performing-agentless-vulnerability-scanning

mukul975/Anthropic-Cybersecurity-Skills · performing-agentless-vulnerability-scanning

0

Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.

performing-lateral-movement-detection

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-detection

0

Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.

detecting-wmi-persistence

mukul975/Anthropic-Cybersecurity-Skills · detecting-wmi-persistence

0

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

performing-lateral-movement-with-wmiexec

mukul975/Anthropic-Cybersecurity-Skills · performing-lateral-movement-with-wmiexec

0

Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.