Hunts supply chain compromise indicators like trojanized updates, compromised dependencies, unauthorized code changes, and tampered builds. For EDR/SIEM threat hunting.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills-zh:hunting-for-supply-chain-compromiseThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
- 主动狩猎环境中供应链入侵指标时
| 概念 | 描述 |
|---|---|
| T1195.001 | 入侵软件依赖项 |
| T1195.002 | 入侵软件供应链 |
| T1199 | 受信关系 |
| 工具 | 用途 |
|---|---|
| CrowdStrike Falcon | EDR 遥测和威胁检测 |
| Microsoft Defender for Endpoint | 基于 KQL 的高级狩猎 |
| Splunk Enterprise | 使用 SPL 查询的 SIEM 日志分析 |
| Elastic Security | 检测规则和调查时间线 |
| Sysmon | 详细的 Windows 事件监控 |
| Velociraptor | 终端工件收集和狩猎 |
| Sigma Rules | 跨平台检测规则格式 |
狩猎 ID:TH-HUNTIN-[日期]-[序号]
技术:T1195.001
主机:[主机名]
用户:[账户上下文]
证据:[日志条目、进程树、网络数据]
风险等级:[严重/高/中/低]
置信度:[高/中/低]
建议措施:[遏制、调查、监控]
npx claudepluginhub killvxk/cybersecurity-skills-zhHunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts.
Hunts supply chain compromise indicators like trojanized updates, compromised dependencies, unauthorized code changes, and tampered build artifacts in EDR/SIEM logs. Useful for threat hunting and incident response.