What problem does it solve?
Security teams struggle to spot attackers moving between internal systems after an initial compromise, because techniques like pass-the-hash, PsExec, and RDP hopping blend into normal east-west traffic. This Skill provides a complete detection workflow that correlates authentication logs, network flows, and service creation events to surface lateral movement before it spreads.
Core Features & Use Cases
- Log Collection Setup: Configures Windows Event Forwarding, Filebeat, and Zeek to capture the exact events (4624, 4625, 4648, 7045, 4768/4769) needed for lateral movement detection.
- Detection Rule Engineering: Provides ready-to-use Splunk SPL, Elastic KQL, and Sigma rules for pass-the-hash, PsExec, and RDP lateral movement mapped to MITRE ATT&CK techniques.
- Network-Level Analysis: Includes Zeek queries and a custom Zeek script that alert on SMB fan-out, admin$ share access, WMI activity, and Kerberos anomalies between internal hosts.
- Use Case: A SOC analyst receives a PsExec alert on a file server at 2 AM and uses this workflow to trace the full attack chain across eight servers, build a timeline, and contain every compromised host.
Quick Start
Ask the AI to build detection rules and Zeek queries for identifying pass-the-hash and PsExec lateral movement across your internal network using your existing Windows event logs and SIEM platform.