LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

Skills tagged: threat-hunting

Browse skills that share this tag.

  • detecting-dcsync-attack-in-active-directory - Detect DCSync credential theft in Active Directory
    threat-huntingactive-directorydcsynccredential-theft

    ★ 8 · Updated 2026-09-17

    Detect DCSync attacks by monitoring non-domain-controller accounts requesting Active Directory replication via DsGetNCChanges.

    ⚙ Identify legitimate domain controllers⚙ Monitor replication rights access GUIDs⚙ Detect non-domain controller replication requests
  • cyber-detecting-t1003-credential-dumping-with-edr - Detecting T1003 Credential Dumping With EDR
    threat-huntingcredential-dumpinglsassmitre-t1003

    ★ 1 · Updated 2026-09-17

    Detect OS credential dumping techniques targeting LSASS memory, SAM, and NTDS using EDR telemetry, Sysmon, and Windows event correlation.

    ⚙ Monitor LSASS process access⚙ Detect credential dumping tools⚙ Monitor NTDS.dit file access
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunt for adversary abuse of signed system binaries (LOLBins)
    threat-huntingmitre-attacklolbinsedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.

    ⚙ Define hunt hypotheses⚙ Identify target LOLBins⚙ Collect process telemetry
  • hunting-for-living-off-the-land-binaries - Hunting for Living-off-the-Land Binaries (LOLBins)
    threat-huntinglolbinsdefense-evasionedr

    ★ 0 · Updated 2026-09-16

    Proactively hunts for adversary abuse of signed system binaries to execute payloads, download files, or proxy execution.

    ⚙ Define hunt hypothesis⚙ Identify target LOLBins⚙ Collect process telemetry
  • detecting-t1548-abuse-elevation-control-mechanism - Detecting T1548 Abuse Elevation Control Mechanism
    threat-huntinguac-bypassprivilege-escalationmitre-t1548

    ★ 0 · Updated 2026-09-15

    Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation using system logs.

    ⚙ Monitor UAC registry modifications⚙ Detect auto-elevating process abuse⚙ Track process integrity level changes
  • yara-authoring - YARA Rule Authoring and Malware Detection
    yaramalware-detectionthreat-huntingsecurity

    ★ 5 · Updated 2026-09-12

    Write and test YARA rules for malware detection, IOC signature creation, threat hunting, and file or directory scanning.

    ⚙ Write YARA rules⚙ Test YARA rules⚙ Detect malware families
  • detecting-insider-threat-behaviors - Detecting Insider Threat Behaviors
    threat-huntingmitre-attackinsider-threatdata-theft

    ★ 3 · Updated 2026-09-12

    Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and data theft.

    ⚙ Formulate detection hypotheses⚙ Identify required data sources⚙ Execute detection queries
  • detecting-mimikatz-execution-patterns - Detecting Mimikatz Execution Patterns
    threat-huntingmitre-attackmimikatzcredential-dumping

    ★ 4 · Updated 2026-09-12

    Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

    ⚙ Formulate detection hypothesis⚙ Identify log data sources⚙ Execute SIEM EDR detection queries
  • hunting-for-cobalt-strike-beacons - Hunting for Cobalt Strike Beacons
    cobalt-strikebeaconthreat-huntingc2

    ★ 4 · Updated 2026-09-11

    Detect Cobalt Strike beacon network activity using default TLS signatures, fingerprints, HTTP C2 profile matching, and jitter analysis.

    ⚙ Detect TLS certificate signatures⚙ Analyze beacon connection intervals⚙ Match HTTP C2 profiles
  • thor-scan - THOR Scan Skill - Generate safe, reproducible scan commands
    security-scanningforensic-toolcommand-line-generationthreat-hunting

    ★ 12 · Updated 2026-02-18

    Produces safe and reproducible command lines for THOR v10/v11 scans on various targets with preflight checks.

    ⚙ detect operating system environment⚙ check THOR version and installation⚙ verify license presence and type
  • secops-hunt - Proactive Threat Hunting for Security Operations
    securitythreat-huntingiocttp

    ★ 22 · Updated 2026-02-11

    Expert guidance for proactive threat hunting to identify undetected threats

    ⚙ check indicator matches⚙ search security events⚙ query UDM data
  • secops-hunt - Proactive Threat Hunting for Security Operations
    securitythreat-huntingcybersecurityincident-response

    ★ 650 · Updated 2026-02-11

    Expert guidance for proactive threat hunting to identify undetected threats

    ⚙ Search for campaign indicators⚙ Check IOC matches⚙ Query UDM data
  • secops-hunt - Proactive Threat Hunting Guidance for Security Operations
    securitythreat-huntingincident-responsesiem

    ★ 528 · Updated 2026-02-11

    Provides expert guidance for proactive threat hunting in security environments

    ⚙ hunt for threat campaigns⚙ search for IOCs⚙ investigate TTPs