{"slug":"analyzing-windows-event-logs-in-splunk","source_name":"analyzing-windows-event-logs-in-splunk","name":"Analyzing Windows Event Logs In Splunk","description":"Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.","version":1,"lift":{"pass_rate_delta_pts":52.17,"pass_rate_pct":52.2,"total_cases":23,"passed_cases":12,"tokens_delta_pct":92.1,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-07-28T00:09:20.560283+00:00"},"skill_score":0.5217,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":52.17,"with_pass_pct":52.2,"without_pass_pct":0,"tokens_delta_pct":92.1,"turns_delta_pct":0,"total_cases":23,"cases_aggregated":23,"verdict":"mixed","never_hurt":true,"completed_at":"2026-07-28T00:09:20.560283+00:00","run_id":"ee114734-45ae-4f6a-ae23-9b6173db3dcb","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":null,"content_status":"clean","indexable":true},"license":"Apache-2.0","install_count":0,"manifest_hash":"f2b01c004aa5a7dfbd498a8f7115e4ccc0ad80ec5d9dbb9f9c7e6f4dbaa80ef5","raw_url":"https://app.decimal.ai/s/analyzing-windows-event-logs-in-splunk/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/analyzing-windows-event-logs-in-splunk"}