New to Claude Skills? Learn how to install them →

Edr skills

Free agent skills tagged edr, ready to install into any SKILL.md-compatible agent.

Detecting Evasion Techniques

mukul975

Identify adversary evasion tactics in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Hunting Advanced Persistent Threats

mukul975

Proactively hunt APT activity in enterprise environments.

Security & ComplianceadvancedPython27.6k repo

Detecting DLL Sideloading Attacks

mukul975

Proactively detect DLL hijacking in enterprise environments.

Security & ComplianceintermediatePython27.6k repo

Detecting Mimikatz Execution Patterns

mukul975

Proactively identify Mimikatz credential dumping activities.

Security & ComplianceintermediatePython27.6k repo

Hunting for Living-off-the-Land Binaries

Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and defense-evasion controls. Use when building LOLBins detection rules for EDR/SIEM or when threat hunting for defense-evasion activity involving trusted system binaries.

Detecting Credential Dumping

Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security event logs. Use when hunting for Mimikatz-style credential theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected credential dumping.

Detecting Process Hollowing Technique

Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child anomalies using EDR telemetry, Volatility's malfind plugin, pe-sieve, Hollows Hunter, and Sysmon Event ID 25. Use when investigating a legitimate-looking process (svchost.exe, explorer.exe, rundll32.exe) suspected of hosting injected code via NtUnmapViewOfSection.

Deploying EDR Agent with CrowdStrike

Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.