ZooWork
ZooWork Market · Skill

implementing-siem-correlation-rules-for-apt

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.

mukul975
mukul975-anthropic-cybersecurity-skills-implementing-siem-correlation-rules-for-apt · v1.0
分类data-analytics
安装次数14
更新时间2026-08-30T10:01:36.742Z
校验状态待验证
implementingsiemcorrelationrules