BigHugger
sk Skill · mukul975

implementing-siem-correlation-rules-for-apt

Write multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1), and network connections (Sysmon Event 3) across hosts within sliding time windows. Use when building SIEM correlation searches to surface multi-stage attack sequences that single-event detections miss, such as…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashsecurity-operationswindows-event-logsPythonapt-detectionlateral-movementcorrelation-rulesyamlsiem
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python