What problem does it solve?
Ransomware operators spend days or weeks inside a network before encryption begins, and most organizations miss the early warning signs. This Skill helps security teams detect ransomware precursor activity—C2 beaconing, credential harvesting, lateral movement, and data staging—during the window where containment can still prevent data loss.
Core Features & Use Cases
- Network Detection Rules: Ready-to-deploy Suricata signatures and Zeek scripts for Cobalt Strike beacons, DCSync, PsExec, internal scans, and RDP brute force.
- SIEM Correlation: Splunk SPL and Microsoft Sentinel KQL queries that chain low-severity precursor events into high-confidence alerts.
- Threat Intelligence Integration: Automated ingestion of abuse.ch Feodo Tracker, URLhaus, ThreatFox, and CISA KEV feeds for ransomware IOCs.
- Use Case: A SOC analyst receives an alert that a workstation connected to 47 internal hosts on port 445 at 2 AM. Using this Skill's workflow, they correlate Zeek conn.log, ssl.log beacon timing, and Kerberos TGS-REQ anomalies to confirm a Cobalt Strike foothold and isolate the host before encryption begins.
Quick Start
Ask the AI to build detection rules for Cobalt Strike beaconing and internal lateral movement using Zeek and Suricata on your network.