Skip to main content

detecting-rdp-brute-force-attacks

Detect RDP brute force attacks by parsing Windows Security Event Logs (EVTX files, via python-evtx) for failed logon patterns (Event ID 4625, Logon Type 10/3), correlating with successful logons (Event ID 4624), and analyzing NLA failures and source IP frequency. Use when investigating exposed RDP endpoints, building SIEM detection rules for credential guessing, or confirming whether a compromised account followed a brute-force pattern.

Zur Installation springen

Quellinformationen

Repository
mukul975/Anthropic-Cybersecurity-Skills
Letzte Quellaktivität
2. August 2026 um 16:32
Erkannte Sprache von SKILL.md
Englisch
Sterne
27.732
Forks
3.366

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.