Lateral Movement Bundle
Auto-curated bundle of 17 skills centered on lateral, movement, persistence, windows, wmi, sysmon.
Browse all skill bundles
Included Skills (200)
- Scheduled Task Threat Hunter — This tool helps security analysts identify malicious persistence and lateral movement by correlating Sysmon and Windows security logs for suspicious scheduled tasks.
- WMI Lateral Movement Hunter — This tool identifies WMI-based lateral movement and persistence by analyzing process creation and activity logs to assist security analysts in threat hunting.
- Registry Persistence Hunter — This tool identifies malicious Windows registry Run key persistence by analyzing Sysmon Event ID 13 logs to assist cybersecurity threat hunters.
- Windows Event Forensics — Analyze Windows Event Logs using specialized tools to detect lateral movement, persistence, and privilege escalation for cybersecurity incident responders and threat hunters.
- Scheduled Task Hunter — This tool facilitates proactive threat hunting for Windows Scheduled Task persistence by guiding security analysts through targeted SIEM and EDR query execution.
- Lateral Movement Detector — This tool assists cybersecurity analysts in identifying adversary lateral movement across networks by executing specialized Splunk SPL queries against Windows authentication logs.
- DCOM Lateral Movement Hunter — This tool assists security analysts in identifying DCOM-based lateral movement by correlating Sysmon events and network traffic to detect suspicious COM object abuse.
- Windows Persistence Hunter — This tool systematically identifies adversary persistence mechanisms across Windows endpoints to assist security analysts during incident response and proactive threat hunting operations.
- Scheduled Task Hunter — This tool identifies adversary persistence by analyzing Windows scheduled task events and suspicious execution patterns to assist security analysts during incident response investigations.
- Windows Threat Analyst — This skill helps SOC analysts and incident responders detect Windows-based threats by executing MITRE-mapped SPL queries against Splunk event logs.
- WMI Persistence Hunter — This tool identifies malicious WMI event subscriptions to help security analysts detect and investigate fileless persistence mechanisms on Windows endpoints.
- APT Correlation Architect — This tool assists security analysts in developing multi-event SIEM correlation rules to detect complex APT lateral movement patterns across Windows environments.
- WMI Persistence Detector — This tool identifies malicious WMI event subscriptions by analyzing Sysmon telemetry to help security analysts and threat hunters detect persistence mechanisms.
- Registry Persistence Hunter — This tool identifies Windows registry-based persistence mechanisms to assist security analysts in proactively detecting and investigating potential malware autostart techniques.
- Windows Forensic Hunter — This tool utilizes Chainsaw to rapidly analyze Windows event logs and forensic artifacts, enabling cybersecurity analysts to perform efficient threat detection and triage.
- Kerberos Attack Detector — This skill identifies Kerberos Pass-the-Ticket attacks by analyzing Windows event logs to assist security analysts in threat hunting and incident response activities.
- Suspicious Service Detector — This tool identifies malicious Windows service installations by analyzing Event ID 7045 logs to help security analysts detect persistence and unauthorized system modifications.
- PowerShell Threat Hunter — This tool assists cybersecurity analysts in identifying malicious activity by parsing Windows Event Logs to detect obfuscated PowerShell commands and bypass techniques.
- Account Manipulation Hunter — This tool identifies Active Directory account tampering and privilege persistence by analyzing critical Windows security event logs for suspicious modification patterns.
- Golden Ticket Detector — This tool identifies Kerberos Golden Ticket forgery by analyzing Windows Event logs for encryption downgrades and abnormal ticket lifetimes to assist security analysts.
- Active Directory Investigator — This tool assists incident responders in identifying attacker persistence and lateral movement by analyzing authentication logs, Kerberos anomalies, and Active Directory metadata.
- Lateral Movement Detector — This tool identifies lateral movement techniques in enterprise networks by analyzing authentication logs and traffic patterns to assist security analysts in threat hunting.
- PowerShell Threat Hunter — This tool enables security analysts to identify malicious PowerShell activity by analyzing EDR and SIEM telemetry for common execution-based attack techniques.
- Lateral Movement Detector — This skill helps SOC teams identify attacker pivoting by correlating endpoint and network telemetry to detect unauthorized lateral movement across internal systems.
- Supply Chain Threat Hunter — This skill performs hypothesis-driven threat hunting across SIEM and EDR logs to detect supply-chain compromises, helping security analysts identify malicious software updates and tampered build artifacts.
- Startup Persistence Hunter — This tool monitors Windows startup directories for unauthorized file creation to help security analysts detect and investigate potential persistence mechanisms used by malware.
- Credential Dumping Detector — This tool identifies credential theft attempts by analyzing Windows logs and SIEM data to assist security analysts in protecting Active Directory environments.
- NTLM Relay Detector — This tool identifies NTLM relay attacks by analyzing Windows Event logs for suspicious authentication patterns, helping security analysts detect unauthorized credential relay activity.
- USB Forensics Analyzer — This tool reconstructs USB device connection history by correlating Windows registry keys and event logs to assist digital forensic investigators in tracking data exfiltration.
- Windows Registry Forensics — Extract and analyze Windows Registry hives to uncover user activity, persistence mechanisms, and system compromise evidence for digital forensics and incident response professionals.
- WMI Lateral Movement — This skill assists red team professionals in executing stealthy lateral movement across Windows networks using WMI-based remote command execution techniques.
- Azure Threat Analyzer — This tool assists security analysts by querying Azure Monitor logs to identify suspicious administrative activity and potential threats within cloud environments.
- RDP Brute-Force Detector — This tool analyzes Windows Security Event Logs to identify and correlate RDP brute-force attack patterns, assisting security analysts in detecting compromised accounts.
- Process Injection Hunter — This tool detects malicious process injection techniques on Windows endpoints by analyzing Sysmon telemetry to assist security analysts in identifying potential defense evasion.
- Zeek Lateral Movement Detector — This tool analyzes Zeek network logs to help security analysts identify and investigate malicious lateral movement techniques across internal network traffic.
- Splunk Threat Enrichment — This skill automates IOC enrichment pipelines in Splunk Enterprise Security to help SOC analysts correlate threat intelligence data and accelerate incident triage.
- Pass-The-Hash Detector — This tool identifies Pass-the-Hash attacks by analyzing NTLM authentication patterns, helping security analysts detect lateral movement and scope potential compromises during incident response.
- Network Anomaly Hunter — This skill performs hypothesis-driven threat hunting by analyzing SIEM and EDR telemetry to identify suspicious command-and-control traffic for cybersecurity professionals and incident responders.
- Webshell Threat Hunter — This skill performs hypothesis-driven threat hunting to detect web shell deployment on internet-facing servers, assisting security analysts in identifying unauthorized persistence and malicious activity.
- Threat Hunt Framework — This skill assists security analysts in transforming threat intelligence into actionable, testable hypotheses for proactive hunting and validation across EDR and SIEM platforms.
- LOLBAS Threat Detector — This skill helps security analysts detect malicious abuse of built-in Windows binaries by leveraging process telemetry, Sysmon data, and Sigma detection rules.
- Empire Artifact Analyzer — This tool identifies PowerShell Empire post-exploitation framework activity within Windows event logs to assist security analysts in detecting malicious C2 staging and execution.
- SIEM Log Onboarding — This skill assists security analysts in systematically integrating, normalizing, and validating new log sources into SIEM platforms to enhance threat detection capabilities.
- Elastic Threat Hunter — This skill enables SOC analysts to perform proactive threat hunting in Elastic SIEM using KQL and EQL to identify sophisticated threats evading automated detection.
- Credential Dumping Detector — This tool identifies OS credential dumping attempts by correlating EDR telemetry and security logs to assist security analysts in proactive threat hunting.
- Spearphishing Threat Hunter — This tool enables cybersecurity analysts to proactively detect targeted spearphishing campaigns by analyzing email logs, endpoint telemetry, and network data for malicious indicators.
- DNS Persistence Hunter — This tool identifies DNS-based persistence mechanisms like hijacking and subdomain takeovers to help security analysts detect unauthorized infrastructure modifications across cloud environments.
- Linux Persistence Analyzer — This tool identifies Linux persistence mechanisms and correlates them with auditd logs to help security analysts reconstruct adversary access timelines during incident response.
- Azure Principal Threat-Hunter — This tool provides KQL detection queries for security analysts to identify and investigate malicious service principal activity within Microsoft Entra ID environments.
- Interactive Malware Sandbox — This tool enables cybersecurity analysts to perform interactive dynamic malware detonation and behavioral analysis using the ANY.RUN cloud sandbox platform for rapid threat investigation.
- Constrained Delegation Exploiter — This tool assists security professionals in identifying and exploiting Kerberos Constrained Delegation misconfigurations to perform lateral movement and privilege escalation within Active Directory environments.
- Privilege Escalation Detector — This skill identifies privilege escalation attempts on Windows and Linux systems to assist security analysts in threat hunting, incident response, and detection validation.
- Entra Offensive Tool Hunter — This skill utilizes KQL to identify offensive Entra ID enumeration tools within Microsoft Sentinel logs, assisting security analysts in detecting unauthorized reconnaissance activity.
- Azure Lateral Detection — This skill assists security analysts in identifying lateral movement within Azure and Entra ID environments using advanced KQL hunting and log correlation.
- Evasion Detection Analyst — This tool identifies adversary defense evasion techniques within endpoint logs to assist security analysts in threat hunting and building robust detection engineering rules.
- Zeek Network Monitor — This skill deploys Zeek to passively analyze network traffic, generating structured logs and custom detection scripts to assist security analysts in threat hunting.
- Insider Threat Investigator — This tool assists SOC analysts in investigating potential insider threats by correlating SIEM, DLP, and HR data to identify unauthorized activities and policy violations.
- API Enumeration Detector — This tool helps security analysts identify BOLA and IDOR attacks by generating SIEM detection rules for suspicious API request patterns and authorization failures.
- DLL Sideloading Detector — This tool identifies malicious DLL side-loading and search-order hijacking by analyzing Sysmon events to assist security analysts in proactive threat hunting efforts.
- DCSync Attack Detector — This tool identifies unauthorized Active Directory replication attempts by monitoring specific event logs to help security analysts detect and mitigate credential theft attacks.
- Service Account Sentinel — This tool helps security analysts detect service account abuse by identifying anomalous interactive logons and privilege escalation patterns within EDR and SIEM telemetry.
- DCSync Attack Detector — This tool identifies unauthorized Active Directory replication requests by monitoring Windows Event ID 4662, assisting security analysts in detecting credential theft attempts.
- PowerShell Log Analyzer — This tool parses Windows PowerShell Script Block logs to help security analysts detect obfuscated commands, malicious payloads, and living-off-the-land attack techniques.
- Cloud Run Manager — This tool helps developers deploy and manage scalable HTTP services, event-driven jobs, and background worker pools on Google Cloud Run infrastructure.
- YARA Threat Hunter — This tool enables security analysts to proactively identify malware and indicators of compromise by scanning files and memory dumps using custom YARA rules.
- Windows Amcache Analyzer — Parses Windows Amcache registry hives to help digital forensics investigators reconstruct program execution timelines and identify malicious software artifacts during incident response.
- Ransomware Defense Hardener — Configures Windows Group Policy Objects to block ransomware execution and lateral movement, helping system administrators secure endpoints against sophisticated cyber threats.
- SSO Token Abuse Hunter — This tool correlates Entra ID and Okta logs to detect stolen session tokens and OAuth replay attacks, assisting security analysts in identifying unauthorized SaaS access.
- Authentication Anomaly Detector — This tool utilizes UEBA analytics and machine learning to help security analysts identify suspicious login behaviors and potential account compromises across authentication logs.
- Forensic Timeline Generator — This tool processes Windows EVTX files using Sigma rules to create prioritized, chronological incident timelines for cybersecurity analysts and digital forensics investigators.
- Process Injection Detector — This tool identifies T1055 process injection techniques by analyzing Sysmon telemetry to help security analysts detect and investigate malicious cross-process memory operations.
- Credential Stuffing Hunter — This tool assists security analysts in identifying credential stuffing attacks by performing statistical analysis on authentication logs to detect anomalous login patterns.
- Windows Prefetch Analyzer — This tool parses Windows Prefetch files to reconstruct application execution history and identify suspicious activity for digital forensics and incident response professionals.
- AWS Lambda — Developers deploy event‑driven functions on AWS Lambda that respond to API Gateway, S3, SQS, DynamoDB streams, and scheduled triggers using Node.js, Python, Go, Rust, Java, or container images. The service scales automatically from zero to thousands of concurrent executions and charges only for actual invocations, enabling teams to run highly scalable, cost‑efficient compute without server management.
- Kubernetes Audit Analyzer — This tool parses Kubernetes API audit logs to identify security threats and generate detection rules, assisting security analysts in investigating cluster compromises.
- Agent Deployment Automator — This tool converts graded Claude Managed Agents into recurring scheduled deployments or event-driven triggers to help developers automate agentic workflows without manual intervention.
- Office365 Compromise Analyzer — This tool parses Microsoft Graph API audit logs to help security analysts detect email forwarding, unauthorized delegation, and suspicious OAuth application grants.
- Data Staging Hunter — This skill identifies potential data exfiltration by monitoring EDR and Sysmon telemetry for suspicious file archiving and staging activities within enterprise environments.
- Event Store Architect — This skill assists software engineers in designing, selecting, and implementing robust event store infrastructure for scalable event-sourced application architectures and data persistence.
- Event Store Architect — This skill assists software engineers in designing, selecting, and optimizing robust event store infrastructure for complex event-sourced application architectures and data persistence.
- Threat Infrastructure Tracker — This tool helps cybersecurity analysts discover and map adversary-controlled infrastructure by pivoting across diverse data sources to support comprehensive threat intelligence investigations.
- Windows Shellbag Analyzer — Analyze Windows Shellbag registry artifacts to reconstruct folder browsing history and verify user interaction with directories for digital forensics and incident response investigations.
- Cloud SIEM Architect — This skill assists security engineers in deploying Microsoft Sentinel to centralize multi-cloud threat detection, automated incident response, and large-scale security telemetry analysis.
- Windows Forensic Analyzer — Automates Windows forensic artifact analysis using Eric Zimmerman's EZ Tools to assist digital forensics investigators in building comprehensive system timelines.
- Active Directory Honeytokens — Deploys deception-based honeytokens and monitoring triggers in Active Directory to help security teams detect lateral movement and unauthorized reconnaissance activities.
- Linux Log Investigator — Analyze Linux system logs to reconstruct user sessions, identify unauthorized access, and establish event timelines for cybersecurity professionals conducting forensic investigations.
- Kerberoasting Attack Detector — This tool identifies Kerberoasting attacks by monitoring anomalous Kerberos TGS requests, helping security analysts detect credential access attempts against Active Directory service accounts.
- Threat Hunting Assistant — This tool assists security analysts in proactive threat hunting, detection engineering, and validating incident response rules against known adversary technique patterns.
- Threat Hunting Assistant — This tool assists security analysts in proactive threat hunting, detection engineering, and validating incident detection rules against known adversary techniques and telemetry.
- Threat Hunting Assistant — This tool assists security analysts in proactive threat hunting, detection engineering, and validating incident detection rules against known adversary techniques and telemetry.
- Malware Eradication Specialist — This tool assists incident responders in systematically removing malware and persistence mechanisms from compromised systems to restore a secure, clean operational state.
- Splunk Detection Engineer — This skill assists security analysts in crafting effective Splunk SPL correlation searches to identify and mitigate potential threats within enterprise SOC environments.
- UEFI Bootkit Analyzer — This tool assists cybersecurity professionals in detecting UEFI firmware implants and persistence mechanisms by leveraging chipsec for comprehensive integrity verification and threat analysis.
- Elastic SIEM Triage — This skill assists SOC analysts in systematically classifying, prioritizing, and investigating security alerts within the Elastic SIEM environment to streamline incident response workflows.
- Linux Audit Investigator — This tool assists security professionals by analyzing Linux audit logs to detect unauthorized access, privilege escalation, and suspicious system activity for incident response.
- Breach Containment Specialist — Executes rapid containment strategies to halt active adversary operations and prevent lateral movement for cybersecurity incident response teams during critical breaches.
- Sigma Rule Generator — Creates portable, vendor-agnostic detection rules for SOC engineers to standardize threat monitoring across diverse SIEM platforms using the Sigma format.
- APT Threat Hunter — This skill assists cybersecurity professionals by performing hypothesis-driven threat hunting across enterprise telemetry to proactively identify and mitigate advanced persistent threats.
- Agent Run Auditor — This tool independently verifies agent execution success by auditing available traces, logs, and artifacts to ensure claims align with objective evidence.
- DNS Tunneling Detector — This tool identifies DNS tunneling and covert data exfiltration by analyzing Zeek logs for anomalous query patterns, helping security analysts detect network threats.
- Agent Run Auditor — This tool independently verifies agent execution success by analyzing traces, logs, and artifacts to ensure claims are supported by objective evidence.
- Insider Threat Detector — This tool identifies malicious or negligent insider activity by analyzing behavioral indicators to assist security analysts in proactive threat hunting and incident investigations.
- Windows Forensic Triage — Automates KAPE artifact collection and parsing to assist incident responders in performing rapid, defensible forensic analysis on Windows systems during early containment.
- Cyber Threat Intelligence — This tool enriches indicators and profiles threat actors using public OSINT sources to assist security analysts in investigating scams and malicious infrastructure.
- Cyber Threat Intelligence — This tool enriches indicators and profiles threat actors using public OSINT sources to assist security analysts in investigating scams and malicious digital activities.
- Cyber Threat Intelligence — This tool enriches threat indicators and profiles threat actors using public OSINT sources to assist security analysts in investigating scams and malicious campaigns.
- AWS Detective Investigator — This tool helps security analysts investigate AWS incidents by leveraging behavior graphs to trace entity timelines and reconstruct attacker activity across cloud environments.
- Threat Actor Mapper — This tool maps threat actor TTPs to the MITRE ATT&CK framework, helping cybersecurity analysts visualize defensive coverage and identify security gaps.
- MISP Threat Intelligence — This skill utilizes PyMISP to automate the creation, enrichment, and sharing of structured threat intelligence for cybersecurity analysts and incident responders.
- UEBA Threat Detection — This skill helps security analysts implement behavioral baselines and anomaly detection in Elasticsearch to identify and alert on potential insider threat activities.
- Splunk Alert Triage — This skill assists SOC analysts in efficiently classifying, investigating, and documenting security alerts within Splunk Enterprise Security to streamline incident response workflows.
- Security Incident Triage — Automates the classification and prioritization of security alerts for SOC analysts using structured incident response playbooks and integrated SIEM data sources.
- UEFI Bootkit Hunter — This tool baselines the EFI System Partition to detect malicious bootkits and unauthorized firmware modifications, assisting security analysts in identifying persistent UEFI-level threats.
- Malware IOC Extractor — Automates the extraction and defanging of malware indicators to help security analysts generate threat intelligence and build effective detection content for defense.
- NetExec Lateral Movement — This tool assists penetration testers in validating credentials, enumerating network services, and executing post-exploitation tasks across diverse protocols within authorized Active Directory environments.
- Network Traffic Forensics — This tool analyzes network traffic captures and flow data to help incident responders identify adversary activity like command-and-control, lateral movement, and data exfiltration.
- Splunk Security Analyst — This skill assists security professionals in investigating incidents by performing log correlation, anomaly detection, and complex SPL query generation within Splunk Enterprise Security.
- Deception Technology Deployment — Deploys honeypots and honeytokens to help SOC teams detect lateral movement and internal reconnaissance with high-fidelity alerts and minimal false positives.
- IOC Enrichment Automator — This skill automates the enrichment of raw indicators of compromise with multi-source threat intelligence to reduce triage time for cybersecurity analysts.
- PEStudio Malware Analyzer — This tool performs static analysis on Windows executables using PEStudio to help security analysts identify malicious indicators and capabilities without executing the binary.
- Canary Token Deployer — Automates the deployment of deception-based canary tokens across network infrastructure to help security teams detect unauthorized access and lateral movement in real-time.
- Adversary Infrastructure Tracker — This tool automates the discovery and mapping of threat actor command-and-control networks by pivoting across DNS, WHOIS, and certificate data for security analysts.
- Incident Response Dashboard — Creates real-time incident response dashboards in SIEM platforms to provide SOC analysts and leadership with critical situational awareness during active security incidents.
- Threat Intelligence Aggregator — This skill automates MISP deployment and feed configuration to help security teams centralize, correlate, and distribute threat intelligence across their security infrastructure.
- clickhouse — The skill executes real‑time analytical queries on massive datasets using a familiar SQL interface, providing advanced aggregation functions and high‑throughput inserts. It supports materialized views for pre‑computed rollups, enabling efficient event tracking, time‑series analytics, and ad‑hoc exploration of billions of rows. Data analysts, engineers, and product teams benefit from fast, scalable analytics on large volumes of data.
- Tamper-Evident Audit — Implement tamper-evident audit logs for compliance, helping developers build secure and compliant applications with immutable event tracking.
- Threat Indicator Manager — Automates the end-to-end lifecycle of threat indicators, helping security analysts maintain high-quality intelligence databases while reducing alert fatigue through systematic enrichment and expiration.
- Microsegmentation Policy Architect — Configures granular microsegmentation policies to enforce least-privilege workload access, helping security engineers prevent lateral movement within zero trust network architectures.
- Shadow Copy Hunt — This skill executes a hypothesis-driven threat hunt for Volume Shadow Copy deletion to help security analysts detect ransomware preparation and anti-forensics activity.
- Malicious URL Analyzer — This tool enables security analysts to safely investigate suspicious URLs by capturing detailed web page behavior and network activity via URLScan.io.
- Mimikatz Detection Tool — This tool identifies Mimikatz credential-dumping activity for security analysts by analyzing command-line patterns, LSASS access signatures, and known binary indicators during threat hunting.
- Network Deception Deployment — This skill assists security professionals in deploying and managing network honeypots to detect unauthorized access, lateral movement, and malicious reconnaissance activities.
- Inngest Workflow Expert — Assists developers in building reliable, event-driven workflows and scheduled jobs using the Inngest durable workflow engine for TypeScript.
- SQL Injection Analyzer — This tool parses WAF logs to identify SQL injection patterns and generate incident reports, assisting security analysts in detecting and tracking malicious attack campaigns.
- API Security Analyzer — This tool parses API gateway access logs to help security analysts detect malicious patterns like BOLA attacks, credential scanning, and rate limit bypasses.
- Insider Threat Detector — Analyzes DLP policy violations and behavioral anomalies to help security analysts identify and investigate potential insider data exfiltration activities.
- Email Compromise Detector — This tool analyzes audit and sign-in logs to help security analysts identify unauthorized mailbox access, malicious forwarding rules, and persistent account takeover attempts.
- Active Directory Tiering — This skill helps security architects implement Microsoft's ESAE tiered administration model to harden Active Directory environments against lateral movement and credential theft.
- CloudTrail Security Analyst — This tool assists security engineers in implementing AWS CloudTrail log analysis to detect unauthorized access, privilege escalation, and suspicious API activity.
- Agent Sandbox — Agent Sandbox executes AI agent code in isolated, resource‑limited environments that block file deletion and restrict network access. It logs every action, producing audit trails that ensure clear accountability. Developers and operators use the sandbox to run AI agents safely and reliably.
- Modbus Traffic Analyzer — This tool monitors Modbus TCP traffic on SCADA and ICS networks to help security analysts detect unauthorized commands and suspicious communication patterns.
- Ransomware Leak Monitor — This tool monitors ransomware data leak sites to extract victim data and generate actionable threat intelligence reports for cybersecurity analysts and risk managers.
- Cross-Platform Automation Tool — Automate web browsers and Windows desktop applications to streamline reverse-engineering workflows, evidence collection, and UI-driven interaction tasks for security researchers and analysts.
- Malware IOC Extractor — This tool automates the identification and extraction of critical indicators of compromise from malicious software to assist cybersecurity analysts in threat intelligence operations.
- Malware Hash Enricher — This tool enriches malware file hashes via VirusTotal API to provide security analysts with critical detection verdicts and contextual threat intelligence.
- PDF Malware Analyzer — This tool assists cybersecurity analysts by performing static structural analysis on suspicious PDF files to identify embedded exploits, malicious scripts, and hidden payloads.
- MISP Threat Automation — This skill automates MISP instance management, threat feed ingestion, and detection rule generation to help security teams streamline intelligence-driven threat detection workflows.
- IOC Enrichment Automator — This tool automates multi-source threat intelligence lookups to provide SOC analysts with rapid contextual scoring and disposition recommendations for incident investigations.
- Proactive Threat Hunting — This skill proactively identifies threats by using hypothesis-driven hunting, IOC analysis, and anomaly detection for security analysts.
- Maltego Transform Builder — Build custom Maltego transforms in Python for visual OSINT graph analysis, helping security researchers and threat intelligence analysts.
- Event Store Architect — This skill assists software engineers in designing, selecting, and implementing robust event storage solutions for complex event-sourced application architectures and infrastructure.
- YARA Malware Triage — Automates malware classification and detection rule creation for security analysts using YARA patterns to identify known threats within suspicious file samples.
- Event Store Architect — This skill assists software engineers in designing, selecting, and implementing robust event storage solutions for complex event-sourced application architectures and infrastructure.
- Cyber Campaign Attribution — This skill assists threat intelligence analysts by systematically evaluating cyber-campaign evidence to generate confidence-weighted attribution assessments using established analytical frameworks like ACH.
- Threat Actor Navigator — This tool generates MITRE ATT&CK Navigator heatmaps to help security analysts visualize threat actor TTPs, identify detection gaps, and prioritize defensive engineering efforts.
- Cloud Abuse Hunter — This tool assists security analysts in identifying adversary abuse of legitimate cloud services for command-and-control, data staging, and unauthorized information exfiltration.
- STIX TAXII Processor — This tool normalizes and routes STIX 2.1 threat intelligence feeds from TAXII servers, helping security analysts automate data ingestion and pipeline validation.
- Windows Shell Reliability — This skill provides developers with best practices for executing commands on Windows by resolving common issues with file paths, character encoding, and redirection.
- Threat Intelligence Analyst — This tool helps security analysts evaluate indicators of compromise by aggregating threat intelligence to determine maliciousness, campaign attribution, and appropriate defensive response actions.
- Phishing Response Automator — This skill automates phishing incident response by integrating with Splunk SOAR to streamline container creation, artifact management, and playbook execution for security analysts.
- Windows Shell Reliability — This skill provides developers with best practices for executing commands on Windows by resolving common issues with file paths, character encoding, and redirection.
- Threat Campaign Correlator — This tool helps cybersecurity analysts identify unified threat campaigns by clustering disparate security incidents, shared indicators, and adversary behaviors across organizational data.
- Data Exfiltration Hunter — This skill analyzes network telemetry to identify and investigate potential data theft, helping security analysts detect unauthorized outbound data transfers and exfiltration attempts.
- Windows Shell Reliability — This skill provides robust patterns for executing commands on Windows, helping developers manage file paths, character encoding, and shell-specific output redirection issues.
- Malicious PDF Analyzer — This tool performs static analysis on suspicious PDF documents to help security analysts identify embedded threats like JavaScript, shellcode, and malicious objects.
- Cloud Storage Anomaly Detector — This skill identifies abnormal cloud storage access patterns for security analysts by monitoring audit logs and analytics to detect potential data exfiltration activities.
- MISP Threat Analyst — This tool queries MISP instances to generate comprehensive threat intelligence reports, helping cybersecurity professionals identify trends, threat actors, and malware families effectively.
- Zeek Beaconing Detector — This tool performs statistical analysis on Zeek connection logs to help security analysts identify potential command-and-control beaconing patterns within network traffic.
- Arkime Network Forensics — Automates Arkime packet capture analysis to help security analysts detect malicious network patterns, investigate suspicious flows, and perform deep forensic packet inspection.
- Web Log Intrusion Analyzer — This tool parses Apache and Nginx logs to identify malicious patterns and anomalies, assisting security analysts in detecting web-based cyber attacks.
- DNS Exfiltration Detector — This tool analyzes Zeek DNS logs to identify data exfiltration and tunneling attempts by detecting high-entropy subdomains and anomalous query patterns for security analysts.
- Rekall Memory Forensics — This tool utilizes the Rekall framework to help security analysts identify malicious artifacts like injected code and hidden processes within Windows memory dumps.
- Cobalt Strike Hunter — This skill identifies Cobalt Strike beacon traffic for security analysts by analyzing TLS fingerprints, malleable C2 profiles, and network behavioral patterns.
- SIEM Detection Optimizer — This skill helps security operations teams reduce alert fatigue by systematically tuning SIEM detection rules and optimizing thresholds to improve incident response precision.
- Windows Unix Utilities — This skill provides instructions for installing BusyBox on Windows, enabling developers to access essential Unix command-line tools within their local environment.
- Windows Unix Utilities — This skill provides instructions for installing and configuring BusyBox on Windows to enable essential Unix command-line tools for developers and system administrators.
- Windows Unix Utilities — This skill guides Windows users through downloading and configuring BusyBox to access essential Unix command-line tools within their local development environment.
- BlueField Security Orchestrator — This skill assists engineers in deploying and configuring the DOCA Argus runtime-security container to monitor BlueField DPU environments and forward security telemetry to SIEM platforms.
- SIEM Detection Engineer — This skill assists SOC teams in designing, testing, and deploying formalized detection rules mapped to MITRE ATT&CK frameworks across various SIEM platforms.
- Segment Data Orchestrator — Streamline Segment customer data platform operations by automating event tracking, user identification, and group management for data engineers and product analysts.
- Windows Prefetch Analyzer — This tool parses Windows Prefetch files to extract execution history and timestamps, assisting forensic investigators in reconstructing program activity during security incident analysis.
- Malware Analysis Assistant — This tool assists security analysts in triaging suspicious files by automating static analysis, IOC extraction, and the generation of YARA and Sigma detection rules.
- Android Malware Analyst — Analyzes suspicious Android APK files using JADX to identify malicious behaviors, data theft, and security threats for cybersecurity researchers and malware analysts.
- Cloud Forensic Investigator — This tool enables security professionals to perform forensic analysis on AWS logs using Athena to detect unauthorized access and potential data exfiltration.
- Algo Trading — The skill constructs end‑to‑end algorithmic trading systems that backtest, develop, and execute strategies while managing risk. It connects to exchange APIs such as Binance, Alpaca, and Interactive Brokers, implements technical indicators, processes market data, and optimizes portfolios. Traders and quantitative analysts use the system to run reliable crypto and traditional market bots that automatically execute orders and enforce risk rules.
- Elevation Control Monitor — Detects privilege escalation attempts and elevation control mechanism abuse to help security analysts identify malicious UAC bypass and unauthorized administrative access.
- Email Forwarding Detector — This tool identifies malicious email forwarding rules to help security analysts detect persistent unauthorized access and prevent business email compromise incidents.
- Cloud Deception Deployer — This tool deploys high-fidelity cloud-native honeytokens across AWS, Azure, and GCP to help security teams detect unauthorized access and lateral movement immediately.
- Windows Forensic Parser — This skill automates the parsing of Windows forensic artifacts using Eric Zimmerman's tools to assist digital forensics and incident response professionals.
- GCP Network Investigator — Troubleshoot Google Cloud networking issues using logs, metrics, and connectivity tests, assisting network engineers and DevOps teams.
- Process Hollowing Detector — This tool assists threat hunters in identifying process hollowing techniques by analyzing memory-mapped sections and system telemetry to uncover malicious code injection.
- DNS Tunneling Detector — This tool identifies covert data exfiltration by analyzing DNS traffic patterns, query entropy, and record payloads to assist security analysts in threat detection.
- AWS Cloud Forensics — This tool assists security responders in investigating AWS account compromises by reconstructing attacker timelines through automated CloudTrail log analysis and event filtering.
- Cloud Run Deployments — Deploys serverless containers on Google Cloud Run, enabling developers to easily manage and scale their applications.
- Cloud Credential Auditor — This tool identifies compromised cloud credentials by analyzing anomalous API activity and threat patterns to assist security teams in rapid incident response.
- Industrial Control Threat Detection — This skill identifies sophisticated cyber-physical attacks by monitoring PLC logic integrity and process anomalies to protect critical infrastructure from nation-state level threats.
- Historian Attack Detector — This tool identifies cyber threats and unauthorized activities on OT historian servers to help security analysts protect critical IT and OT network bridges.
- S3 Exfiltration Detector — This tool identifies unauthorized bulk data transfers and suspicious access patterns in AWS S3 buckets to help security teams mitigate potential data breaches.
- Certificate Transparency Auditor — This tool monitors public CT logs to help security teams detect unauthorized certificate issuance, discover subdomains, and identify potential phishing infrastructure.
- Office Malware Analyzer — This tool assists cybersecurity analysts by deobfuscating and investigating malicious VBA macros within Microsoft Office documents to identify potential attack chains and payloads.