Results for “auth-logs”
17 skillsAnalyzing Linux System Artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
24.6k · bundle
Hunting Credential Stuffing Attacks
Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins using statistical analysis on Splunk or raw log data.
24.6k · bundle
Detecting Lateral Movement In Network
Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
24.6k · bundle
More results
Performing Linux Log Forensics Investigation
Analyze Linux system logs including auth.log, syslog, systemd journal, and auditd to reconstruct user activity, detect unauthorized access, and establish event timelines on compromised systems.
24.6k · bundle
Auth
Use when implementing login, registration, session handling, protected routes, or role-based access.
0
Auth
Opens a browser for login and captures an authentication token for AEM Edge Delivery Services admin APIs.
142 · bundle
Github Auth
GitHub auth setup: HTTPS tokens, SSH keys, gh CLI login.
1 · bundle
Github Auth
GitHub auth setup: HTTPS tokens, SSH keys, gh CLI login.
0 · bundle
Session Logs
Search and analyze your own session logs (older/parent conversations) using jq.
0
Session Logs
Search and analyze your own session logs (older/parent conversations) using jq.
0
Session Logs
Search and analyze your own session logs (older/parent conversations) using jq.
0
Session Logs
Search and analyze your own session logs (older/parent conversations) using jq.
0
Debug Logging
debug-logging
1
Diary
Unified Diary System: A context-preserving automated logger for multi-project development.
2 · bundle
Detecting Lateral Movement With Splunk
Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
24.6k · bundle
Implementing Siem Correlation Rules For Apt
Detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
24.6k · bundle
Performing Active Directory Compromise Investigation
Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy changes, and Kerberos ticket anomalies to identify attacker persistence and lateral movement paths.
24.6k · bundle