UEBA auth-anomaly detector — detect brute-force, spraying, and impossible travel
Defensive UEBA playbook for detecting anomalous authentication patterns: brute-force and password-spraying detection, impossible travel and geo-velocity, credential stuffing, token misuse, privilege abuse — with SIEM correlation, SOAR triage, and incident response checklists
- What
- Defensive UEBA playbook for detecting anomalous authentication patterns: brute-force and password-spraying detection, impossible travel and geo-velocity, credential stuffing, token misuse, privilege abuse — with SIEM correlation, SOAR triage, and incident response checklists
- Cost
- Free
- Needs
- 90 days of authentication baseline data; a SIEM (Splunk, Elastic, Azure Sentinel); GeoIP enrichment; Python 3.9+; this is defensive detection engineering (blue team), not offensive tooling
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @mukul975's detecting-anomalous-authentication-patterns skill (frontmatter author: `mahipal`; credited to @mukul975 as the repo publisher), listed here with credit to its creator: a defensive UEBA playbook for authentication telemetry. It guides the agent through detecting anomalous authentication patterns — brute-force attacks, password spraying, credential stuffing, impossible travel and geo-velocity analysis, token misuse, and privilege abuse — with correlation rules, baseline establishment, anomaly thresholds, SIEM/SOAR integration guidance, and incident-response triage checklists. Explicitly defensive: this is detection engineering and incident response, not offensive tooling — it helps blue teams find and triage attacks, never build them; no attack payloads, no exploit code. Honest caveats: needs 90 days of authentication baseline data plus a SIEM (Splunk/Elastic/Azure Sentinel), GeoIP enrichment, and Python 3.9+ — without baseline telemetry the detection patterns have nothing to compare against; thresholds will need tuning to your environment. Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: 90 days of authentication baseline data; a SIEM (Splunk, Elastic, Azure Sentinel); GeoIP enrichment; Python 3.9+; this is defensive detection engineering (blue team), not offensive tooling Install "UEBA auth-anomaly detector — detect brute-force, spraying, and impossible travel" for me. It gives my agent @mukul975's defensive UEBA playbook for authentication telemetry: detecting anomalous authentication patterns (brute-force, password spraying, credential stuffing, impossible travel/geo-velocity, token misuse, privilege abuse) with correlation rules, baseline establishment, anomaly thresholds, SIEM/SOAR integration guidance, and incident-response triage checklists. Apache-2.0 licensed. Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-anomalous-authentication-patterns/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting, or anything offensive — this should be defensive detection content only). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "detecting-anomalous-authentication-patterns". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm 90 days of auth baseline data exists; wire up SIEM export (Splunk/Elastic/Sentinel) with GeoIP enrichment; tune anomaly thresholds to my environment; this is defensive detection — no attack payloads, no exploit code). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.