LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: defense-evasion

Browse skills that share this tag.

  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunt for adversary abuse of signed system binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.

    ⚙ Define hunt hypotheses⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntinglolbinsdefense-evasionedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • detecting-credential-dumping-techniques - Detecting Credential Dumping Techniques
    credential-dumpinglsassmimikatzsysmon

    ★ 12 · Updated 2026-09-11

    Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

    ⚙ Configure Sysmon for ProcessAccess logging⚙ Forward Sysmon and Windows logs⚙ Create GrantedAccess detection rules
  • T1550.001_application-access-token - Use stolen application access tokens for authentication bypass
    mitre-attackenterprisedefense-evasionlateral-movement

    ★ 3,096 · Updated 2026-05-28

    Use stolen application access tokens to bypass authentication and access restricted accounts, information, or services.

    ⚙ steal application access tokens⚙ bypass authentication process⚙ access restricted accounts