★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.
Browse skills that share this tag.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.
★ 12 · Updated 2026-09-11
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
★ 3,096 · Updated 2026-05-28
Use stolen application access tokens to bypass authentication and access restricted accounts, information, or services.