★ 8 · Updated 2026-09-17
Detect DCSync attacks by monitoring non-domain-controller accounts requesting Active Directory replication via DsGetNCChanges.
Browse skills that share this tag.
★ 8 · Updated 2026-09-17
Detect DCSync attacks by monitoring non-domain-controller accounts requesting Active Directory replication via DsGetNCChanges.
★ 1 · Updated 2026-09-17
Detect OS credential dumping techniques targeting LSASS memory, SAM, and NTDS using EDR telemetry, Sysmon, and Windows event correlation.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.
★ 0 · Updated 2026-09-16
Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.
★ 0 · Updated 2026-09-15
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation using system logs.
★ 5 · Updated 2026-09-12
Write and test YARA rules for malware detection, IOC signature creation, threat hunting, and file or directory scanning.
★ 3 · Updated 2026-09-12
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and data theft.
★ 4 · Updated 2026-09-12
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
★ 4 · Updated 2026-09-11
Detect Cobalt Strike beacon network activity using default TLS signatures, fingerprints, HTTP C2 profile matching, and jitter analysis.
★ 12 · Updated 2026-02-18
Produces safe and reproducible command lines for THOR v10/v11 scans on various targets with preflight checks.
★ 22 · Updated 2026-02-11
Expert guidance for proactive threat hunting to identify undetected threats
★ 650 · Updated 2026-02-11
Expert guidance for proactive threat hunting to identify undetected threats
★ 528 · Updated 2026-02-11
Provides expert guidance for proactive threat hunting in security environments