defense-threat-hunting
Installation
SKILL.md
Threat hunting
When it applies
You suspect activity that evaded detections, or you want to proactively look for a specific technique/actor. Hunting assumes breach and searches telemetry for evidence, rather than waiting for an alert.
Why it works
Detections encode what you already anticipated; hunting finds what you didn't. Framing a falsifiable hypothesis around an ATT&CK technique focuses the search on data that would prove or disprove compromise, and every confirmed pattern becomes a new detection — so coverage grows.