Detecting Evasion Techniques In Endpoint Logs

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005.

theheavenlyd3mon 2baf70c 8 files · 39.7 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-evasion-techniques-in-endpoint-logs commit 2baf70ccd3

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-evasion-techniques-in-endpoint-logs