detecting-ntlm-relay-with-event-correlation
bfoxhound/Anthropic-Cybersecurity-SkillsDetect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning…
Scores out of 100 · grade B+
2026-08-23Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
- repo is less than two weeks old
Adopted
20% of the score0/100
- No install or star signal yet.
Documented
15% of the score100/100
- 4,097 words with worked examples.
- Ships 5 bundled files.
Install
npx skills add bfoxhound/Anthropic-Cybersecurity-Skills/detecting-ntlm-relay-with-event-correlationWhat it says it does
Detect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDAP signing, and flagging NTLMv2-to-NTLMv1 downgrades. Use for hunting credential relay in NTLM-enabled AD, investigating auth-source anomalies, building SIEM correlation rules, or responding to PetitPotam/DFSCoerce/PrinterBug alerts.
Also in bfoxhound/Anthropic-Cybersecurity-Skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| abusing-dpapi-for-credential-accessbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| abusing-shadow-credentials-for-privescbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| acquiring-disk-image-with-dd-and-dcflddbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-apt-group-with-mitre-navigatorbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-browser-forensics-with-hindsightbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-disk-image-with-autopsybfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today |
Other ai & agents skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| mcp-builderanthropics/skills | No license | AI & agents | 105,342 installs | yesterday | |
| agent-developmentanthropics/claude-plugins-official | clean | AI & agents | 5,913 installs | today | |
| plugin-settingsanthropics/claude-plugins-official | clean | AI & agents | 5,476 installs | today | |
| skill-creatoranthropics/claude-plugins-official | clean | AI & agents | 5,853 installs | today | |
| microsoft-foundrymicrosoft/azure-skills | clean | AI & agents | 545,599 installs | yesterday | |
| comfyuiNousResearch/hermes-agent | clean | AI & agents | 234k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=bfoxhound%2FAnthropic-Cybersecurity-Skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
