Skip to main content

Skills neste repositório

AgentFlocks/flocks - Página 7

O SkillsMP coletou 771 skills de AgentFlocks/flocks. Abra uma skill para revisar a origem e os detalhes.

AgentFlocks/flocks

Mostrando 40 de 771 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Discover and inventory shadow API endpoints that operate outside documented specifications using traffic analysis, code scanning, and API discovery platforms.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns. Parses ModSecurity audit logs and JSON WAF event logs to identify SQLi patterns (UNION SELECT, OR 1=1, SLEEP(), BENCHMARK()), tracks attack sources, correlates…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers detecting sophisticated cyber-physical attacks that follow the Stuxnet attack pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation from operators. It addresses PLC logic integrity monitoring, physics-based…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect suspicious PowerShell execution patterns including encoded commands, download cradles, AMSI bypass attempts, and constrained language mode evasion.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-child process relationships.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including feed integration capability, STIX/TAXII support, workflow automation, analyst interface, and total cost of ownership. Use when conducting a TIP…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 771 skills coletadas.