configuring-windows-event-logging-for-detection

mukul975/configuring-windows-event-logging-for-detection · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Configures Windows Advanced Audit Policy, event log sizes, and Windows Event Forwarding to generate high-fidelity security events for threat detection and SIEM ingestion.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. implementing-cloud-trail-log-analysis · mukul975 bundle
    Analyze AWS CloudTrail logs for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration.
    24.6k
    repo stars
  2. hunting-for-data-exfiltration-indicators · mukul975 bundle
    Analyze network traffic, logs, and data flows to detect potential data exfiltration via DNS tunneling, cloud storage uploads, encrypted channels, and other indicators of compromise.
    24.6k
    repo stars
  3. detection-engineering-coverage-evaluation · google
    Automates detection engineering workflows in Google SecOps by extracting threat intelligence, generating detection opportunities, simulating attacker behavior with synthetic events, evaluating rule coverage, and creating new YARA-L 2.0 rules to close gaps.
    14.4k
    repo stars
  4. hunting-for-scheduled-task-persistence · mukul975 bundle
    Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
    24.6k
    repo stars
  5. deploying-active-directory-honeytokens · mukul975 bundle
    Deploys deception-based honeytokens in Active Directory, including fake privileged accounts, SPNs for Kerberoasting detection, decoy GPOs with cpassword traps, and deceptive BloodHound paths, with monitoring for Windows Security Event IDs.
    24.6k
    repo stars
  6. processing-stix-taxii-feeds · mukul975 bundle
    Processes STIX 2.1 threat intelligence bundles from TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to consuming systems.
    24.6k
    repo stars

Frequently asked questions

How do I install the configuring-windows-event-logging-for-detection skill?

Run npx skillmds add mukul975/configuring-windows-event-logging-for-detection in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the configuring-windows-event-logging-for-detection skill do?

Configures Windows Advanced Audit Policy, event log sizes, and Windows Event Forwarding to generate high-fidelity security events for threat detection and SIEM ingestion. It is listed under Security, DevOps & Infra, Incident Response, Monitoring & Observability on SkillMD.

Is configuring-windows-event-logging-for-detection safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with configuring-windows-event-logging-for-detection?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is configuring-windows-event-logging-for-detection free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published configuring-windows-event-logging-for-detection?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.