Threat Hunting skills
Free agent skills tagged threat hunting, ready to install into any SKILL.md-compatible agent.
68 skills
Hunting for Suspicious Scheduled Tasks
mukul975
Identify and analyze potential persistence threats in Windows.
Detecting NTLM Relay
mukul975
Identify NTLM relay attacks through event correlation.
Detecting DCSync Attack
mukul975
Identify and respond to DCSync attacks in Active Directory.
Hunting for LOLBins Execution
mukul975
Detect and analyze LOLBins in endpoint logs.
Hunting for Living-off-the-Land Binaries
mukul975
Proactively detect malicious use of trusted system binaries.
Generating Forensic Timelines
mukul975
Transform Windows event logs into actionable forensic timelines.
Hunting EVTX with Chainsaw
mukul975
Rapidly analyze Windows event logs for threats.
Fleet Hunting with Velociraptor
mukul975
Conduct fleet-wide threat hunts with deep endpoint visibility.
Detecting T1055 Process Injection
mukul975
Identify and analyze process injection techniques using Sysmon.
Hunting for WMI Persistence
mukul975
Detect and analyze WMI-based persistence mechanisms.
Hunting for Beaconing
mukul975
Detect command-and-control beaconing in network traffic.
Implementing Velociraptor for IR Collection
mukul975
Streamline endpoint forensic artifact collection for incident response.
Detecting Credential Dumping
mukul975
Identify and respond to credential theft in your environment.
Detecting Entra Offensive Tools
mukul975
Identify malicious activity in Microsoft Graph logs.
DNS Tunneling Detection with Zeek
mukul975
Identify covert data exfiltration via DNS queries.
Detecting Evasion Techniques
mukul975
Identify adversary evasion tactics in endpoint logs.
Hunting SaaS SSO Token Abuse
mukul975
Detect and mitigate token replay attacks in SaaS environments.
Deploying Osquery for Endpoint Monitoring
mukul975
Real-time endpoint monitoring with SQL-based queries.
Hunting for DCOM Lateral Movement
mukul975
Detect DCOM abuse for enhanced cybersecurity.
Detecting T1548 Abuse
mukul975
Identify UAC bypass and privilege escalation attempts.
Hunting Bootkits in EFI
mukul975
Detect and analyze UEFI bootkits on your systems.
Detecting Network Anomalies with Zeek
mukul975
Enhance network security with passive monitoring and anomaly detection.
Hunting Advanced Persistent Threats
mukul975
Proactively hunt APT activity in enterprise environments.
YARA-X Rule Authoring
trailofbits
Create effective malware detection rules with YARA-X.
