Sysmon skills
Free agent skills tagged sysmon, ready to install into any SKILL.md-compatible agent.
10 skills
Hunting for DCOM Lateral Movement
mukul975
Detect DCOM abuse for enhanced cybersecurity.
Detecting T1055 Process Injection
mukul975
Identify and analyze process injection techniques using Sysmon.
Analyzing Windows Event Logs in Splunk
mukul975
Detect Windows-based threats using Splunk queries.
Detecting Malicious Scheduled Tasks
mukul975
Identify and analyze malicious tasks in Windows systems.
Detecting WMI Persistence
mukul975
Identify and analyze WMI-based persistence mechanisms.
Detecting Credential Dumping Techniques
mukul975
Identify and respond to credential theft on Windows systems.
Detecting Living Off the Land
mukul975
Identify abuse of Windows binaries for threat detection.
Hunting for Registry Run Key Persistence
mukul975
Detect malicious registry persistence mechanisms in Windows.
Hunting for Lateral Movement via WMI
mukul975
Detect WMI-based lateral movement in Windows environments.
Hunting for Process Injection Techniques
mukul975
Detect and analyze process injection techniques on Windows.
