hunt-threat
Installation
SKILL.md
Advanced Threat Hunting Skill
Conduct proactive, hypothesis-driven threat hunts based on threat intelligence, observed anomalies, or specific TTPs.
Inputs
HUNT_HYPOTHESIS- Clear statement of the hunt objective (required)- Example: "Suspected DNS tunneling for C2 based on recent actor TTPs"
- Example: "Anomalous PowerShell execution on critical servers"
- Example: "Living-off-the-land techniques bypassing EDR"
- (Optional)
RELEVANT_GTI_REPORTS- GTI Collection IDs or report names - (Optional)
TARGET_SCOPE_QUERY- UDM query to narrow initial scope TIME_FRAME_HOURS- Lookback period (default: 168 = 7 days)- (Optional)
HUNT_CASE_ID- case for tracking the hunt