Implementing Siem Correlation Rules For Apt

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.

theheavenlyd3mon 924396b 4 files · 25.8 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/implementing-siem-correlation-rules-for-apt commit 924396b90f

Frequently asked questions

npx skillmds add theheavenlyd3mon/implementing-siem-correlation-rules-for-apt