From asi
Detects LOLBins/LOLBAS abuse (certutil, regsvr32, mshta, rundll32) via Sysmon process telemetry, Sigma rules, and parent-child analysis for threat hunting and SOC investigations.
npx claudepluginhub plurigrid/asi --plugin asiThis skill uses the workspace's default tool permissions.
Living Off the Land Binaries, Scripts, and Libraries (LOLBAS) are legitimate system utilities abused by attackers to execute malicious actions while evading detection. This skill covers detecting abuse of certutil.exe, regsvr32.exe, mshta.exe, rundll32.exe, msbuild.exe, and other LOLBins using process telemetry from Sysmon and Windows Event Logs, combined with Sigma rule-based detection.
Detects LOLBin abuse including certutil, regsvr32, mshta, rundll32 via Sysmon telemetry, Sigma rules, and parent-child analysis. For threat hunting, SOC incident response, and detection rule building.
Detects LOLBin/LOLBAS abuse including certutil, regsvr32, mshta, rundll32 via Sysmon telemetry, Sigma rules, and parent-child process analysis for threat hunting.
Detects abuse of Windows LOLBins like certutil, rundll32, and mshta in living-off-the-land attacks. Analyzes Sysmon logs, process creation, command lines, and parent-child relations for SIEM rules and threat hunting.
Share bugs, ideas, or general feedback.
Living Off the Land Binaries, Scripts, and Libraries (LOLBAS) are legitimate system utilities abused by attackers to execute malicious actions while evading detection. This skill covers detecting abuse of certutil.exe, regsvr32.exe, mshta.exe, rundll32.exe, msbuild.exe, and other LOLBins using process telemetry from Sysmon and Windows Event Logs, combined with Sigma rule-based detection.