hunt-apt

Installation
SKILL.md

APT Threat Hunt Skill

Proactively hunt for TTPs and IOCs associated with a specific Advanced Persistent Threat (APT) group based on threat intelligence.

Inputs

  • THREAT_ACTOR_ID - GTI Collection ID or name of the target APT group
  • HUNT_TIMEFRAME_HOURS - Lookback period (default: 168 = 7 days)
  • (Optional) TARGET_SCOPE_QUERY - UDM query to narrow scope
  • (Optional) HUNT_HYPOTHESIS - Specific hypothesis guiding the hunt
  • (Optional) HUNT_CASE_ID - SOAR case for tracking

Workflow

Step 1: Identify Actor & Gather Intelligence

Installs
1
First Seen
Apr 29, 2026
hunt-apt from smithery.ai