hunting-threats

Installation
SKILL.md

Hunting Threats

Hunting starts from an assumption of failure: the controls are deployed, no alert has fired, and the adversary may still be present. The output is not usually a compromise — it is a detection, a telemetry gap, or a documented negative result. Hunts that only count as successful when they find something degrade into confirmation bias.

When to Use

  • Proactively searching for compromise that detection missed
  • Testing a specific hypothesis about attacker behaviour in your environment
  • Operationalizing a threat intel report against your telemetry
  • Validating that a control or detection actually works in production
  • Baselining an environment to enable future outlier analysis

When NOT to Use

Installs
22
GitHub Stars
146
First Seen
Jul 31, 2026
hunting-threats — trilwu/secskills