Threat Hunting skills
Free agent skills tagged threat hunting, ready to install into any SKILL.md-compatible agent.
68 skills
Detecting NTLM Relay
mukul975
Identify NTLM relay attacks through event correlation.
Hunting for DCOM Lateral Movement
mukul975
Detect DCOM abuse for enhanced cybersecurity.
Hunting Bootkits in EFI
mukul975
Detect and analyze UEFI bootkits on your systems.
Hunting SaaS SSO Token Abuse
mukul975
Detect and mitigate token replay attacks in SaaS environments.
Detecting Entra Offensive Tools
mukul975
Identify malicious activity in Microsoft Graph logs.
Detecting Evasion Techniques
mukul975
Identify adversary evasion tactics in endpoint logs.
Implementing Velociraptor for IR Collection
mukul975
Streamline endpoint forensic artifact collection for incident response.
Hunting EVTX with Chainsaw
mukul975
Rapidly analyze Windows event logs for threats.
Hunting for LOLBins Execution
mukul975
Detect and analyze LOLBins in endpoint logs.
DNS Tunneling Detection with Zeek
mukul975
Identify covert data exfiltration via DNS queries.
Hunting for WMI Persistence
mukul975
Detect and analyze WMI-based persistence mechanisms.
Detecting T1548 Abuse
mukul975
Identify UAC bypass and privilege escalation attempts.
Hunting for Suspicious Scheduled Tasks
mukul975
Identify and analyze potential persistence threats in Windows.
Detecting Network Anomalies with Zeek
mukul975
Enhance network security with passive monitoring and anomaly detection.
Hunting Advanced Persistent Threats
mukul975
Proactively hunt APT activity in enterprise environments.
DNR Hunt
anthropics
Proactive threat hunting for logs and source code.
YARA-X Rule Authoring
trailofbits
Create effective malware detection rules with YARA-X.
Detecting Process Hollowing Technique
mukul975
Identify and analyze process hollowing threats effectively.
Data Exfiltration Hunting
mukul975
Proactively detect data theft through network analysis.
Detecting Lateral Movement with Splunk
mukul975
Hunt for adversary lateral movement using Splunk.
Detecting DLL Sideloading Attacks
mukul975
Proactively detect DLL hijacking in enterprise environments.
Hunting for C2 Beaconing
mukul975
Proactively detect command and control beaconing in networks.
Building Threat Hunt Hypothesis Framework
mukul975
Systematize your threat hunting with structured hypotheses.
Hunting For Registry Persistence
mukul975
Proactively detect Windows registry persistence mechanisms.
