LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

detecting-lateral-movement-in-network - Detect Lateral Movement in Enterprise Networks

Identifies lateral movement by analyzing authentication logs, network flows, SMB traffic, and RDP sessions with Zeek, Velociraptor, and SIEM rules.

Tags

Updated: 2026-10-02

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Analyze authentication logs
  • Correlate SIEM events
  • Detect SMB movement
  • Detect RDP movement
  • Detect PsExec activity
  • Detect pass-the-hash
  • Hunt anomalous traffic
  • Generate SIEM rules
  • Configure Zeek detection
  • Validate network segmentation

Inputs

  • Windows Security Event Logs
  • DNS and network flow data
  • SMB and DCE-RPC logs
  • RDP session data
  • Internal authentication baseline
  • Zeek logs
  • SIEM data

Outputs

  • Lateral movement alerts
  • SIEM detection rules
  • Sigma rule files
  • Zeek detection notices
  • Threat-hunting findings
  • Attack-path timelines

Requirements

  • Internal network monitoring
  • SIEM platform
  • Windows Event Forwarding
  • Zeek, Suricata, or network TAPs
  • MITRE ATT&CK knowledge
  • Normal traffic baseline
  • Monitoring configuration privileges

Source

  • Spec: SKILL.md
network-security
lateral-movement
threat-detection
siem
pass-the-hash
Analyze authentication logs
Correlate SIEM events
Detect SMB movement
Detect RDP movement
Windows Security Event Logs
DNS and network flow data
SMB and DCE-RPC logs
Lateral movement alerts
SIEM detection rules
Sigma rule files