mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-04 18:00:18 +03:00
Rewrite 548 skill descriptions to the activation rubric
Each rewritten description now states both what the skill does (concrete capability, named tools/artifacts) and an explicit when-to-use trigger, improving agent discovery/activation. Grounded in each skill's own body; changes confined to the `description` field only (bodies and all other frontmatter untouched). Produced by a gated audit->rewrite->recheck loop (548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded). Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
@@ -1,8 +1,6 @@
|
||||
---
|
||||
name: detecting-pass-the-ticket-attacks
|
||||
description: Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event
|
||||
IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic
|
||||
SIEM
|
||||
description: Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM. Use when investigating incidents involving stolen or replayed Kerberos tickets, building detection rules or threat hunting queries for ticket abuse, or validating SOC monitoring coverage for credential-theft attack techniques.
|
||||
domain: cybersecurity
|
||||
subdomain: threat-detection
|
||||
tags:
|
||||
|
||||
Reference in New Issue
Block a user