Edr skills
Free agent skills tagged edr, ready to install into any SKILL.md-compatible agent.
8 skills
Detecting Evasion Techniques
mukul975
Identify adversary evasion tactics in endpoint logs.
Hunting Advanced Persistent Threats
mukul975
Proactively hunt APT activity in enterprise environments.
Detecting DLL Sideloading Attacks
mukul975
Proactively detect DLL hijacking in enterprise environments.
Detecting Mimikatz Execution Patterns
mukul975
Proactively identify Mimikatz credential dumping activities.
Hunting for Living-off-the-Land Binaries
Proactively hunts for adversary abuse of legitimate, signed system binaries (LOLBins) used to execute malicious payloads, download files, or proxy execution while evading application allowlisting and defense-evasion controls. Use when building LOLBins detection rules for EDR/SIEM or when threat hunting for defense-evasion activity involving trusted system binaries.
Detecting Credential Dumping
Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security event logs. Use when hunting for Mimikatz-style credential theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected credential dumping.
Detecting Process Hollowing Technique
Detect process hollowing (MITRE T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child anomalies using EDR telemetry, Volatility's malfind plugin, pe-sieve, Hollows Hunter, and Sysmon Event ID 25. Use when investigating a legitimate-looking process (svchost.exe, explorer.exe, rundll32.exe) suspected of hosting injected code via NtUnmapViewOfSection.
Deploying EDR Agent with CrowdStrike
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
