47+AI
ZH

全站搜索

用自然语言找工具、提示词、技能、MCP 与工作流。

已理解: 

共 0 条

提示词 6

查看全部

analyzing-windows-event-logs-in-splunk

编程协作 · skill · agent-skill · analyzing · windows · event · logs · in · splunk

在 Splunk 中分析 Windows 安全日志、系统日志与 Sysmon 事件日志,通过映射到 MITRE ATT&CK

3.2万+

detecting-t1055-process-injection-with-sysmon

编程协作 · skill · agent-skill · detecting · t1055 · process · injection · with · sysmon

通过分析 Sysmon 事件 ID 1、7、8、10 和 25 中的跨进程内存操作、远程线程创建以及异常的 DLL

3.2万+

detecting-wmi-persistence

编程协作 · WMI 持久化检测 · 威胁狩猎分析 · Sysmon 日志审查 · MITRE 攻击映射 · Windows 取证调查

通过分析 Sysmon 事件 ID 19、20 和 21(分别对应恶意的 EventFilter、EventConsumer 和 FilterToConsume…

3.1万+

hunting-for-data-staging-before-exfiltration

编程协作 · skill · agent-skill · hunting · for · data · staging · before · exfiltration

通过分析 EDR/Sysmon 进程创建和文件系统遥测(Event ID 4688、Sysmon 1/11),检测 7-Zip/RAR/tar 归档创建、异常的…

3.1万+

detecting-malicious-scheduled-tasks-with-sysmon

编程协作 · Sysmon 计划任务检测 · 恶意持久化识别 · Windows 日志关联 · 威胁狩猎分析 · 计划任务监控

使用 Sysmon 事件 ID 1(schtasks.exe 的进程创建)、11(任务 XML 的文件创建)以及 Windows 安全事件 4698/4702 …

3.1万+