Repository
OTRF/ThreatHunter-Playbook agent skills
- skills
- 5
- GitHub stars
- 4.7k
GitHub description: “A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.”
- Stars
- 4,683 (867 forks)
- Licence
- MIT
- Last push
- Jan 2026
- Created
- Mar 2017
- threat-hunting
- sysmon
- hunting-campaigns
- hypothesis
- hunting
- dfir
- hunter
- mitre-attack-db
- mitre
Install all skills
npx skills add OTRF/ThreatHunter-PlaybookAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in OTRF/ThreatHunter-Playbook, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics. | OTRF/ | 4.7k | — | ~1.2k | Automated safety check: Pass | MIT | 9 mo ago |
| 2 | Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written. | OTRF/ | 4.7k | — | ~813 | Automated safety check: Pass | MIT | 9 mo ago |
| 3 | Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern. | OTRF/ | 4.7k | — | ~600 | Automated safety check: Pass | MIT | 9 mo ago |
| 4 | Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. | OTRF/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | 9 mo ago |
| 5 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 9 mo ago |
Questions, answered from the data.
What is the best skill in OTRF/ThreatHunter-Playbook?
Threat Hunt Blueprint Assembly from OTRF/ThreatHunter-Playbook ranks first of the 5 skills in OTRF/ThreatHunter-Playbook listed here, with the highest score: its repository has 4.7k GitHub stars, its SKILL.md loads about 1.2k tokens and it passes the automated safety check with no findings. Next come Hunt Data Source Identification and Hunt Focus Definition.
Are the skills in OTRF/ThreatHunter-Playbook official?
None yet. All 5 skills in OTRF/ThreatHunter-Playbook listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from OTRF/ThreatHunter-Playbook?
Run npx skills add OTRF/ThreatHunter-Playbook in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.