AGENTIC SEARCH
Search
</> Advanced
Federated search across
all connected repositories
Snowflake Splunk Sentinel Databricks +9
Find me lunar spider activity techniques across all of my data platforms
+
Data Feeds
Detections
Hunting
AGENTIC INVESTIGATIONS
Threat Scenario — Possible Lunar Spider Activity
Agent Verdict Suspicious
Confidence High
Summary: Suspicious activity on ADMIN-WKS-129 by mont.donaldrundll32.exe, encoded PowerShell, and AD recon suggest an attempt at persistence and internal reconnaissance.
Event Timeline
11:18 AM
Suspicious rundll32 Execution
11:19 AM
Create / Modify Schtasks
11:21 AM
Encoded PowerShell Command
11:22 AM
AdFind Commands
AGENTIC DETECTION ENG.
Blueprints Detection Engineering — Daily Intel Instructions
Paragraph
Activity
Condition
1
Intel Report Intake
Gather daily threat intel.
2
Detection Gap Analysis
Identify detections to fill gaps.
3
Create Detections
Build from available feeds.
Human Approval Gate
APPROVED
4
Deploy Detections
Roll out new detections.
5
Validate Detections
Run attack simulations.