Skill Market

Debugging

Debugging utilities

detecting container drift at runtime

GitHub

Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting credential dumping techniques

GitHub

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting cryptomining in cloud

GitHub

'This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting dcsync attack in active directory

GitHub

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting dnp3 protocol anomalies

GitHub

'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting email account compromise

GitHub

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting evasion techniques in endpoint logs

GitHub

'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting fileless malware techniques

GitHub

'Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting golden ticket attacks in kerberos logs

GitHub

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting golden ticket forgery

GitHub

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting insider threat with ueba

GitHub

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting lateral movement in network

GitHub

'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting lateral movement with splunk

GitHub

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting living off the land with lolbas

GitHub

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting malicious scheduled tasks with sysmon

GitHub

'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting modbus command injection attacks

GitHub

'Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting pass the ticket attacks

GitHub

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting process hollowing technique

GitHub

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting process injection techniques

GitHub

'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting rdp brute force attacks

GitHub

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting rootkit activity

GitHub

'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting shadow it cloud usage

GitHub

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting stuxnet style attacks

GitHub

'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents

detecting suspicious oauth application consent

GitHub

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit

0.0
(0)
0 installs33.4K GitHub stars
Debugginggithubcommunityai-agents