home/categories/computational-chemistry/mukul975-anthropic-cybersecurity-skills-skills-detecting-wmi-persistence-skill-md
computational-chemistryresearch
detecting-wmi-persistence
Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
maintainer
mukul975
업데이트됨 4/6/2026
스타
4240
포크
464
quick start
Installation and usage
Detect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
설치
$ install --globalskills.sh
사용법
설치 후 터미널에서 다음 명령을 실행하여 이 스킬을 사용할 수 있습니다:
skills use detecting-wmi-persistence