hunt-analytics-generation
SKILL.md
Generating Analytics
This skill translates hunt investigative intent into a small set of analytics that describe how adversary behavior should manifest in data.
It is executed during hunt planning, after sufficient context has been established, and before queries are executed or detections are validated.
This skill focuses on behavior modeling, not determining what is suspicious or anomalous, which requires broader environmental context beyond adversary descriptions or schema inspection.
Workflow
- You MUST complete each step in order and MUST NOT proceed until the current step is complete.
- You MUST NOT read reference documents unless the current step explicitly instructs you to do so.
- You MUST NOT execute queries or validate results in this skill.
- You MUST NOT introduce new research about system internals or adversary tradecraft.
- You MAY retrieve table schemas using platform tools when explicitly instructed.