All authors

Claude Skills by mukul975
github.com/mukul9751,113 skills6 installs1,639 views
- Detecting Container Escape AttemptsContainer escape is a critical attack technique where an adversary breaks out of container isolation to accessVotes: 0GitHub stars: 31,965
- Detecting Container Escape With Falco RulesDetect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, fileVotes: 0GitHub stars: 31,965
- Detecting Credential Dumping TechniquesDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, WindowsVotes: 0GitHub stars: 31,965
- Detecting Cryptomining In Cloud'This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operationsVotes: 0GitHub stars: 31,965
- Detecting Dcsync Attack In Active DirectoryDetect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashesVotes: 0GitHub stars: 31,965
- Detecting Deepfake Audio In Vishing Attacks'Detects AI-generated deepfake audio used in voice phishing (vishing) attacks by extracting spectral featuresVotes: 0GitHub stars: 31,965
- Detecting Dll Sideloading AttacksDetect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijackVotes: 0GitHub stars: 31,965
- Detecting Dnp3 Protocol Anomalies'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoringVotes: 0GitHub stars: 31,965
- Detecting Dns Exfiltration With Dns Query AnalysisDetect data exfiltration through DNS tunneling by analyzing query entropy, subdomain length, query volume, TXTVotes: 0GitHub stars: 31,965
- Detecting Email Account CompromiseDetect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-inVotes: 0GitHub stars: 31,965
- Detecting Email Forwarding Rules AttackDetect malicious email forwarding rules created by adversaries to maintain persistent access to email communicationsVotes: 0GitHub stars: 31,965
- Detecting Evasion Techniques In Endpoint Logs'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,Votes: 0GitHub stars: 31,965
- Detecting Exfiltration Over Dns With ZeekDetect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous queryVotes: 0GitHub stars: 31,965
- Detecting Fileless Attacks On Endpoints'Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent filesVotes: 0GitHub stars: 31,965
- Detecting Fileless Malware Techniques'Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,Votes: 0GitHub stars: 31,965
- Detecting Golden Ticket Attacks In Kerberos LogsDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryptionVotes: 0GitHub stars: 31,965
- Detecting Golden Ticket ForgeryDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),Votes: 0GitHub stars: 31,965
- Detecting Insider Data Exfiltration Via Dlp'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies,Votes: 0GitHub stars: 31,965
- Detecting Insider Threat BehaviorsDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads,Votes: 0GitHub stars: 31,965
- Detecting Insider Threat With UebaImplement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculateVotes: 0GitHub stars: 31,965
- Detecting Kerberoasting AttacksDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts withVotes: 0GitHub stars: 31,965
- Detecting Lateral Movement In Network'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,Votes: 0GitHub stars: 31,965
- Detecting Lateral Movement With SplunkDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,Votes: 0GitHub stars: 31,965
- Detecting Lateral Movement With Zeek'Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log,Votes: 0GitHub stars: 31,965
- Detecting Living Off The Land Attacks'Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors processVotes: 0GitHub stars: 31,965
- Detecting Living Off The Land With LolbasDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32Votes: 0GitHub stars: 31,965
- Detecting Malicious Scheduled Tasks With Sysmon'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),Votes: 0GitHub stars: 31,965
- Detecting Mimikatz Execution PatternsDetect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memoryVotes: 0GitHub stars: 31,965
- Detecting Misconfigured Azure Storage'Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryptionVotes: 0GitHub stars: 31,965
- Detecting Mobile Malware Behavior'Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuseVotes: 0GitHub stars: 31,965
- Detecting Modbus Command Injection Attacks'Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorizedVotes: 0GitHub stars: 31,965
- Detecting Modbus Protocol Anomalies'This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems.Votes: 0GitHub stars: 31,965
- Detecting Network Anomalies With Zeek'Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generateVotes: 0GitHub stars: 31,965
- Detecting Network Scanning With Ids SignaturesDetect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detectionVotes: 0GitHub stars: 31,965
- Detecting Ntlm Relay With Event Correlation'Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 forVotes: 0GitHub stars: 31,965
- Detecting Oauth Token Theft'Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft EntraVotes: 0GitHub stars: 31,965
- Detecting Pass The Hash AttacksDetect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM whereVotes: 0GitHub stars: 31,965
- Detecting Pass The Ticket AttacksDetect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalousVotes: 0GitHub stars: 31,965
- Detecting Port Scanning With Fail2ban'Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts,Votes: 0GitHub stars: 31,965
- Detecting Privilege Escalation AttemptsDetect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernelVotes: 0GitHub stars: 31,965
- Detecting Privilege Escalation In Kubernetes PodsDetect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, andVotes: 0GitHub stars: 31,965
- Detecting Process Hollowing TechniqueDetect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-childVotes: 0GitHub stars: 31,965
- Detecting Process Injection Techniques'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,Votes: 0GitHub stars: 31,965
- Detecting Qr Code Phishing With Email SecurityDetect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding maliciousVotes: 0GitHub stars: 31,965
- Detecting Ransomware Encryption Behavior'Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, andVotes: 0GitHub stars: 31,965
- Detecting Ransomware Precursors In Network'Detects early-stage ransomware indicators in network traffic before encryption begins, including initial accessVotes: 0GitHub stars: 31,965
- Detecting Rdp Brute Force AttacksDetect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (EventVotes: 0GitHub stars: 31,965
- Detecting Rootkit Activity'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modifiedVotes: 0GitHub stars: 31,965
- Detecting S3 Data Exfiltration Attempts'Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs,Votes: 0GitHub stars: 31,965
- Detecting Serverless Function Injection'Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, GoogleVotes: 0GitHub stars: 31,965