BigHugger
sk Skill · mukul975

hunting-for-t1098-account-manipulation

Hunts for MITRE ATT&CK T1098 account manipulation — shadow admin creation, SID history injection, group membership changes, and credential modifications — by analyzing Windows Security Event Log IDs 4738, 4728, 4732, 4756, 4670, and 5136. Use when investigating suspected privilege persistence in Active Directory, after detecting anomalous group/credential changes, or during incident response to trace account…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonpersistenceactive-directoryaccount-manipulationt1098mitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python