Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses statistical analysis on Splunk or raw log data. Use when investigating account takeover campaigns or building detection rules for auth abuse.
Installs into .claude/skills of the current project.
Are you the author of Cyber Hunting Credential Stuffing Attacks?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nexuslinkproductions-cyber-hunting-credential-stuffing-attacks)
---
name: cyber-hunting-credential-stuffing-attacks
description: "Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. Uses statistical analysis on Splunk or raw log data. Use when investigating account takeover campaigns or building detection rules for auth abuse."
hide: true
---
<!-- GENERATED:YURI-CODEX-SKILL-ADAPTER:v1 -->
# YURI skill adapter
Authoritative source: `.claude/skills/cyber-hunting-credential-stuffing-attacks/SKILL.md`
Authoritative source SHA-256: `f421a6f38674a852d142054d45b30769695532656f57ff64e1efb2213173ebe4`
Source class: `cyber-armed`
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run `node _SYSTEM/Scripts/skill-recall.mjs --show cyber-hunting-credential-stuffing-attacks` and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.