LogoClawIndex
CasesSkillsAbout
LogoClawIndex

detecting-living-off-the-land-attacks - Detect suspicious Windows LOLBin activity

Detects abuse of legitimate Windows binaries by analyzing process creation, command lines, parent-child relationships, and network activity.

Tags

Updated: 2026-10-07

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Configure LOLBin-focused Sysmon monitoring
  • Author Sigma detection rules
  • Analyze Sysmon event logs
  • Correlate process and network activity
  • Validate detection rules
  • Tune detection false positives

Inputs

  • Windows endpoint telemetry
  • Sysmon configuration
  • Security process creation logs
  • Sigma rule repository
  • LOLBAS reference
  • Atomic Red Team test cases

Outputs

  • LOLBin-focused Sysmon configuration
  • Sigma detection rules
  • Suspicious execution findings
  • Validated detection results
  • False-positive tuning guidance

Requirements

  • Windows endpoints
  • Sysmon v15 or later
  • SIEM ingesting specified Sysmon events
  • Windows Security event forwarding
  • Python 3.8 or later
  • Python evtx and pandas packages
  • LOLBAS project reference
  • Sigma rule repository

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
cybersecurity
threat detection
LOLBins
living off the land
fileless attacks
process monitoring
Sysmon
Sigma
Configure LOLBin-focused Sysmon monitoring
Author Sigma detection rules
Analyze Sysmon event logs
Correlate process and network activity
Windows endpoint telemetry
Sysmon configuration
Security process creation logs
LOLBin-focused Sysmon configuration
Sigma detection rules
Suspicious execution findings