Implementing Siem Correlation Rules For Apt

Write multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1), and network connections (Sysmon Event 3) across hosts within sliding time windows. Use when building SIEM correlation searches to surface multi-stage attack sequences that single-event detections miss, such as pass-the-hash or lateral movement chains.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/implementing-siem-correlation-rules-for-apt commit 6c4516834b

Frequently asked questions

npx skillmds@latest add gabrielmoreira/implementing-siem-correlation-rules-for-apt