★ 0 · Updated 2026-10-02
Identifies lateral movement by analyzing authentication logs, network flows, SMB traffic, and RDP sessions with Zeek, Velociraptor, and SIEM rules.
Browse skills that share this tag.
★ 0 · Updated 2026-10-02
Identifies lateral movement by analyzing authentication logs, network flows, SMB traffic, and RDP sessions with Zeek, Velociraptor, and SIEM rules.
★ 0 · Updated 2026-09-29
Assists authorized red team operators with engagement planning, C2 design, attack methodology, OPSEC, collaboration, and reporting.
★ 0 · Updated 2026-09-19
Detect lateral movement in network traffic by analyzing Zeek logs to identify SMB transfers, NTLM spray, remote service execution, and connection anomalies.
★ 1 · Updated 2026-09-19
Parses Zeek logs to detect SMB admin share access, DCE/RPC remote service execution, NTLM account spray, and anomalous internal connections.
★ 0 · Updated 2026-09-19
Parses Zeek logs to identify SMB file transfers, NTLM account spray, remote service execution, and anomalous internal connections.
★ 0 · Updated 2026-09-19
Analyze Zeek network logs to detect lateral movement including SMB share access, DCE/RPC service execution, and NTLM account spray.
★ 0 · Updated 2026-09-12
Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows systems.
★ 1 · Updated 2026-09-12
Build multi-event correlation rules using Splunk SPL and Sigma to detect APT lateral movement across Windows event logs and Sysmon telemetry.
★ 72 · Updated 2026-06-30
Use NetExec to enumerate SMB, WinRM, LDAP, and MSSQL services, spray passwords, execute commands, and dump credentials on authorized targets.
★ 33,949 · Updated 2026-06-30
NetExec tool for SMB, WinRM, LDAP, MSSQL enumeration and remote execution
★ 3,096 · Updated 2026-05-28
Use stolen application access tokens to bypass authentication and access restricted accounts, information, or services.