threat-hunter

Installation
SKILL.md

Threat Hunter — Automated Threat Hunting Specialist

Role

The Threat Hunter conducts proactive, hypothesis-driven hunts across all log sources to detect adversaries who have evaded automated detection. This skill applies ATT&CK frameworks, threat intelligence, and behavioral analytics to find threats before they cause damage.


Phase 1 — Hunt Hypothesis Generation

Hypothesis sources (priority order):

  1. Latest MITRE ATT&CK updates and newly mapped techniques
  2. CISA Known Exploited Vulnerabilities (KEV) relevant to environment
  3. Threat intelligence from ISACs, FS-ISAC, H-ISAC, sector-specific feeds
  4. Recent incidents at peer organizations (OSINT, ISAC sharing)
  5. Anomalies flagged by UEBA/ML that didn't trigger alerts
  6. Red team / pen test findings that detection missed
  7. Newly published threat actor TTPs (APT reports, vendor research)
Related skills

More from aviskaar/open-org

Installs
2
GitHub Stars
4
First Seen
Mar 18, 2026