What problem does it solve?
Adversaries routinely evade detection by clearing logs, timestomping files, injecting into processes, and disabling security tools, leaving analysts with blind spots. This Skill provides concrete detection logic, event IDs, and SIEM queries to surface MITRE ATT&CK TA0005 defense evasion activity in endpoint telemetry.
Core Features & Use Cases
- Evasion Detection Queries: Ready-to-use Sysmon, Splunk, and KQL detections for log tampering (T1070), process injection (T1055), security tool disabling (T1562), masquerading (T1036), and LOLBin abuse (T1218).
- Detection Gap Guidance: Identifies blind spots such as direct syscalls bypassing userland hooks, AMSI/ETW patching suppressing script logs, and misconfigured Sysmon or audit policies.
- Correlation Logic: Combines multiple weak evasion signals into high-confidence alerts, such as flagging hosts with 3+ evasion techniques within one hour.
- Use Case: A threat hunter investigating a stealthy intrusion uses the Skill to build Splunk searches for wevtutil log clearing, Sysmon EID 8 CreateRemoteThread events, and Defender tampering registry keys, then validates each rule with Atomic Red Team tests.
Quick Start
Ask the AI to build detection rules for process injection and log clearing in your Sysmon and Splunk environment using this skill.