detecting-lateral-movement-in-network

mukul975/detecting-lateral-movement-in-network · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.7 KB
  • 📁scripts
  • ⚙️agent.py 7.9 KB
  • 📄LICENSE 11.0 KB

Related

  1. hunting-advanced-persistent-threats · mukul975 bundle
    Proactively hunts for Advanced Persistent Threat activity using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts.
    24.6k
    repo stars
  2. performing-lateral-movement-detection · mukul975 bundle
    Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques.
    24.6k
    repo stars
  3. analyzing-windows-event-logs-in-splunk · mukul975 bundle
    Detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement by analyzing Windows Security, System, and Sysmon event logs in Splunk using SPL queries mapped to MITRE ATT&CK techniques.
    24.6k
    repo stars
  4. implementing-siem-correlation-rules-for-apt · mukul975 bundle
    Detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts using Splunk SPL and Sigma rule format.
    24.6k
    repo stars
  5. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  6. hunting-for-lateral-movement-via-wmi · mukul975 bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-lateral-movement-in-network skill?

Run npx skillmds add mukul975/detecting-lateral-movement-in-network in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-lateral-movement-in-network skill do?

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems. It is listed under Security, Coding & Dev Tools, Incident Response, Vulnerability Scanning on SkillMD.

Is detecting-lateral-movement-in-network safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-lateral-movement-in-network?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-lateral-movement-in-network free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-lateral-movement-in-network?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.