Agent skill

Detecting Lateral Movement With Zeek

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis.

Apache-2.0Auto-check passedSecurity

Install Detecting Lateral Movement With Zeek

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-lateral-movement-with-zeek -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-lateral-movement-with-zeek --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-lateral-movement-with-zeek .claude/skills/detecting-lateral-movement-with-zeek && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-lateral-movement-with-zeek
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
502 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis.

  • Works in 6 steps: Verify Zeek Log Collection → Parse conn.log for Internal Lateral… → Analyze SMB Admin Share Access → …
  • Tasks that involve Red teaming and adversary simulation
  • SKILL.md covers When to Use, Prerequisites, Workflow and Verification
  • Runs Python scripts from its folder; calls python3

What it does

Detecting Lateral Movement With Zeek is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smbmapping.log, smbfiles.log, dcerpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Red teaming and adversary simulation

Example prompts

  • “/detecting-lateral-movement-with-zeek”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Verify Zeek Log Collection
  2. Parse conn.log for Internal Lateral Patterns
  3. Analyze SMB Admin Share Access
  4. Detect DCE/RPC Remote Service Operations
  5. Detect NTLM Account Spray
  6. Run the Automated Analysis Agent

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Lateral Movement With Zeek loads about 1.9k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 502 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 502 words, ~1,930 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-lateral-movement-with-zeek/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
detecting-lateral-movement-with-zeek
description
Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
domain
cybersecurity
subdomain
network-security
tags
zeek, lateral-movement, smb, dce-rpc, ntlm-spray, network-forensics
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557, T1071, T1021

Detecting Lateral Movement with Zeek

Analyze Zeek network logs to identify lateral movement techniques including SMB admin share access, DCE/RPC remote service creation, NTLM account spray, Kerberos ticket anomalies, and large internal data transfers indicative of staging or exfiltration between hosts.

When to Use

  • Hunting for lateral movement after an initial compromise indicator is found on one endpoint
  • Investigating suspected NTLM account spray or Pass-the-Ticket attacks across the internal network
  • Monitoring SMB traffic for unauthorized file transfers to admin shares (C$, ADMIN$, IPC$)
  • Detecting remote service execution via DCE/RPC (PsExec, schtasks, WMI lateral patterns)
  • Building alerting rules for internal network anomalies in a Zeek-based NSMP deployment
  • Performing post-incident timeline reconstruction using Zeek logs as a network-level evidence source

Do not use as a standalone detection mechanism. Zeek sees network traffic only; combine with endpoint telemetry (Sysmon, EDR) for full visibility. Encrypted SMB3 traffic may limit Zeek's visibility into file-level details.

Prerequisites

  • Zeek 6.0+ deployed on a network tap or SPAN port monitoring internal VLAN traffic
  • Zeek SMB analyzer enabled (loaded by default: @load base/protocols/smb)
  • Zeek DCE/RPC analyzer enabled (@load base/protocols/dce-rpc)
  • Zeek Kerberos analyzer enabled (@load base/protocols/krb)
  • Python 3.8+ (standard library only)
  • Access to Zeek log directory (default: /opt/zeek/logs/current/)
  • Familiarity with Zeek TSV log format (fields separated by \t, header lines prefixed with #)

Workflow

Step 1: Verify Zeek Log Collection

Confirm that Zeek is producing the required log files for lateral movement detection:

bash
# Check that all required analyzers are producing logs
ls -la /opt/zeek/logs/current/conn.log
ls -la /opt/zeek/logs/current/smb_mapping.log
ls -la /opt/zeek/logs/current/smb_files.log
ls -la /opt/zeek/logs/current/dce_rpc.log
ls -la /opt/zeek/logs/current/kerberos.log
ls -la /opt/zeek/logs/current/ntlm.log

# Quick field check on conn.log
zeek-cut id.orig_h id.resp_h id.resp_p proto service < /opt/zeek/logs/current/conn.log | head -20
Step 2: Parse conn.log for Internal Lateral Patterns

Identify connections between internal hosts on lateral-movement-associated ports:

bash
# Extract SMB connections (port 445) between internal hosts
zeek-cut ts id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes \
  < /opt/zeek/logs/current/conn.log \
  | awk '$5 == 445 && $7 == "smb"'

# Extract DCE/RPC connections (port 135)
zeek-cut ts id.orig_h id.resp_h id.resp_p service \
  < /opt/zeek/logs/current/conn.log \
  | awk '$4 == 135'

# Extract WinRM connections (port 5985/5986)
zeek-cut ts id.orig_h id.resp_h id.resp_p service \
  < /opt/zeek/logs/current/conn.log \
  | awk '$4 == 5985 || $4 == 5986'
Step 3: Analyze SMB Admin Share Access

Detect access to administrative shares (C$, ADMIN$, IPC$) which is the primary vector for tools like PsExec:

bash
# Check smb_mapping.log for admin share access
zeek-cut ts id.orig_h id.resp_h path share_type \
  < /opt/zeek/logs/current/smb_mapping.log \
  | grep -iE '(C\$|ADMIN\$|IPC\$)'

# Check smb_files.log for file writes to admin shares
zeek-cut ts id.orig_h id.resp_h action path name size \
  < /opt/zeek/logs/current/smb_files.log \
  | grep -i 'SMB::FILE_WRITE'

Deploy the following Zeek script to generate notice.log alerts on admin share access:

zeek
@load base/protocols/smb
@load base/frameworks/notice

redef enum Notice::Type += {
    Admin_Share_Access
};

event smb1_tree_connect_andx_request(c: connection, hdr: SMB1::Header, path: string, service: string) {
    if ( /\$/ in path )
        NOTICE([$note=Admin_Share_Access,
                $msg=fmt("Admin share access: %s -> %s (%s)", c$id$orig_h, c$id$resp_h, path),
                $conn=c]);
}
Step 4: Detect DCE/RPC Remote Service Operations

Monitor for remote service creation and scheduled task registration via DCE/RPC:

bash
# Look for service control manager operations (PsExec pattern)
zeek-cut ts id.orig_h id.resp_h endpoint operation \
  < /opt/zeek/logs/current/dce_rpc.log \
  | grep -iE '(svcctl|atsvc|ITaskSchedulerService)'
Show full SKILL.md (199 more words)Show less
Step 5: Detect NTLM Account Spray

Analyze ntlm.log for authentication anomalies indicating credential reuse. Zeek's ntlm.log does not expose password hashes, so this detection identifies a single account authenticating to many hosts in a short window — the network signature of credential spraying tools like CrackMapExec:

bash
# Extract NTLM authentications
zeek-cut ts id.orig_h id.resp_h username domainname server_nb_computer_name success \
  < /opt/zeek/logs/current/ntlm.log

# Failed NTLM authentications (brute force or credential testing)
zeek-cut ts id.orig_h id.resp_h username success \
  < /opt/zeek/logs/current/ntlm.log \
  | awk '$5 == "F"'

# Sort by timestamp for timeline analysis
zeek-cut ts id.orig_h id.resp_h username success \
  < /opt/zeek/logs/current/ntlm.log \
  | sort -k1,1

Deploy the following Zeek script to generate notice.log alerts when a single account touches more hosts than the threshold in a rolling window:

zeek
@load base/protocols/ntlm
@load base/frameworks/notice

redef enum Notice::Type += {
    NTLM_Account_Spray
};

global ntlm_tracker: table[string] of set[addr] &create_expire=5min;
const spray_threshold = 3 &redef;

event ntlm_log(rec: NTLM::Info) {
    if ( ! rec?$username || rec$username == "-" )
        return;
    if ( rec$username !in ntlm_tracker )
        ntlm_tracker[rec$username] = set();
    add ntlm_tracker[rec$username][rec$id$resp_h];
    if ( |ntlm_tracker[rec$username]| >= spray_threshold )
        NOTICE([$note=NTLM_Account_Spray,
                $msg=fmt("NTLM account spray: %s -> %d hosts", rec$username, |ntlm_tracker[rec$username]|),
                $sub=rec$username,
                $conn=rec$id]);
}
Step 6: Run the Automated Analysis Agent

Use the provided agent.py for comprehensive lateral movement detection:

bash
python3 agent.py /opt/zeek/logs/current/
python3 agent.py /opt/zeek/logs/2026-03-18/  # Analyze a specific date

Verification

  • Confirm conn.log captures internal SMB (port 445) and DCE/RPC (port 135) connections with correct field parsing
  • Verify smb_mapping.log correctly logs admin share paths (C$, ADMIN$, IPC$)
  • Test with a known PsExec execution in a lab: expect to see SMB FILE_WRITE of the service binary followed by DCE/RPC svcctl CreateService
  • Validate NTLM log parsing by performing a test authentication and confirming username, domain, and success fields are captured; verify the NTLM Account Spray Zeek script generates a notice.log entry when the spray threshold is exceeded
  • Cross-reference Zeek alerts with Sysmon Event ID 1 (Process Creation) on the target host to confirm end-to-end detection
  • Verify the agent correctly handles both TSV and JSON Zeek log formats

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/detecting-lateral-movement-with-zeek of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Lateral Movement With Zeek next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Lateral Movement With Zeek compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Lateral Movement With Zeek this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Authorization Bypass DetectionTencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0
Run Assert Evalresponsibleai/ASSERT330—~11kAutomated safety check: NotesMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Lfd Designelvisun/loss-function-development176—~2.9kAutomated safety check: NotesMIT
Acl AbuseADScanPro/Claude-AD211—~2.6kAutomated safety check: PassMIT

Similar skills

  • Authorization Bypass Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

    6.8k GitHub stars~753 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Run Assert Eval

    responsibleai/ASSERT

    Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

    330 GitHub stars~11k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Lfd Design

    elvisun/loss-function-development

    Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).

    176 GitHub stars~2.9k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    211 GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web Exfiltration Detection

    Tencent/AI-Infra-Guard

    Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

    6.8k GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Detecting Lateral Movement With Zeek

What does Detecting Lateral Movement With Zeek do?

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Detecting Lateral Movement With Zeek is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis.

When should I use Detecting Lateral Movement With Zeek?

Detecting Lateral Movement With Zeek fits situations like: tasks that involve Red teaming and adversary simulation.

How do I install Detecting Lateral Movement With Zeek in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-lateral-movement-with-zeek -a claude-code`. Or copy the skill folder (skills/detecting-lateral-movement-with-zeek in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-lateral-movement-with-zeek in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Lateral Movement With Zeek in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-lateral-movement-with-zeek -a codex`. Or copy the skill folder (skills/detecting-lateral-movement-with-zeek in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-lateral-movement-with-zeek in your project. Codex loads it when a task matches its description.

Can I use Detecting Lateral Movement With Zeek in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-lateral-movement-with-zeek -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-lateral-movement-with-zeek, .gemini/skills/detecting-lateral-movement-with-zeek, .github/skills/detecting-lateral-movement-with-zeek and .opencode/skills/detecting-lateral-movement-with-zeek in your project.

What does Detecting Lateral Movement With Zeek need to run?

Going by SKILL.md and its folder, Detecting Lateral Movement With Zeek needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Detecting Lateral Movement With Zeek access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detecting Lateral Movement With Zeek safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Lateral Movement With Zeek use?

Detecting Lateral Movement With Zeek is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Lateral Movement With Zeek use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Lateral Movement With Zeek?

Skills that share tags, products or a category with Detecting Lateral Movement With Zeek: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 330 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Lateral Movement With Zeek?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.