Debugging
Debugging utilities
detecting container drift at runtime
GitHubDetect unauthorized modifications to running containers by monitoring for binary execution drift, file system
detecting credential dumping techniques
GitHubDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows
detecting cryptomining in cloud
GitHub'This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations
detecting dcsync attack in active directory
GitHubDetect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
detecting dnp3 protocol anomalies
GitHub'Detect anomalies in DNP3 (Distributed Network Protocol 3) communications used in SCADA systems by monitoring
detecting email account compromise
GitHubDetect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in
detecting evasion techniques in endpoint logs
GitHub'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping,
detecting fileless malware techniques
GitHub'Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection,
detecting golden ticket attacks in kerberos logs
GitHubDetect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
detecting golden ticket forgery
GitHubDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17),
detecting insider threat with ueba
GitHubImplement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate
detecting lateral movement in network
GitHub'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows,
detecting lateral movement with splunk
GitHubDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs,
detecting living off the land with lolbas
GitHubDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32
detecting malicious scheduled tasks with sysmon
GitHub'Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe),
detecting modbus command injection attacks
GitHub'Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized
detecting pass the ticket attacks
GitHubDetect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous
detecting process hollowing technique
GitHubDetect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child
detecting process injection techniques
GitHub'Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing,
detecting rdp brute force attacks
GitHubDetect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event
detecting rootkit activity
GitHub'Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified
detecting shadow it cloud usage
GitHubDetect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow
detecting stuxnet style attacks
GitHub'This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying
detecting suspicious oauth application consent
GitHubDetect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit