Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .claude/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add alirezarezvani/claude-skills --skill threat-detection -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .agents/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add alirezarezvani/claude-skills --skill threat-detection -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .cursor/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add alirezarezvani/claude-skills --skill threat-detection -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .gemini/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add alirezarezvani/claude-skills --skill threat-detection -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .github/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add alirezarezvani/claude-skills --skill threat-detection -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "threat-detection" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/threat-detection into .opencode/skills/threat-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-detection", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
threat-detection
GitHub stars
28k
Token cost
~3.5k tokens
SKILL.md length
1,361 words
Files
3 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT
At a glance
A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
Works in 4 steps: Review threat intelligence feeds for… → Map last 30 days of security alerts to… → Score top 5 hypotheses with… → …
Hunting for threats in an environment
SKILL.md covers Table of Contents, Overview, Threat Signal Analyzer and Threat Hunting Methodology, plus 7 more sections
Runs Python scripts from its folder; calls python3
What it does
Threat Detection is an agent skill from alirezarezvani/claude-skills. Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, z-score anomaly detection, and MITRE ATT&CK-mapped signal prioritization.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/hunt-playbooks.md` and `scripts/threat_signal_analyzer.py`).
It sits in Security, covering Anomaly detection, Security operations and Prioritization frameworks. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.
When your agent uses it
Hunting for threats in an environment
Detecting behavioral anomalies in telemetry
Example prompts
“/threat-detection”
Requirements
Python 3
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Review threat intelligence feeds for sector-relevant TTPs
2Map last 30 days of security alerts to ATT&CK tactics to identify gaps
3Score top 5 hypotheses with threat_signal_analyzer.py hunt mode
4Prioritize by score — start with highest
What it can do on your machine
Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Threat Detection loads about 3.5k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,361 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~66
When it runs· the whole SKILL.md, loaded when a task matches
~3.5k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~5.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/threat-detection/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
threat-detection
description
Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, z-score anomaly detection, and MITRE ATT&CK-mapped signal prioritization.
Threat Detection
Threat detection skill for proactive discovery of attacker activity through hypothesis-driven hunting, IOC analysis, and behavioral anomaly detection. This is NOT incident response (see incident-response) or red team operations (see red-team) — this is about finding threats that have evaded automated controls.
This skill provides the methodology and tooling for proactive threat detection — finding attacker activity through structured hunting hypotheses, IOC analysis, and statistical anomaly detection before alerts fire.
Distinction from Other Security Skills
Skill
Focus
Approach
threat-detection (this)
Finding hidden threats
Proactive — hunt before alerts
incident-response
Active incidents
Reactive — contain and investigate declared incidents
red-team
Offensive simulation
Offensive — test defenses from attacker perspective
cloud-security
Cloud misconfigurations
Posture — IAM, S3, network exposure
Prerequisites
Read access to SIEM/EDR telemetry, endpoint logs, and network flow data. IOC feeds require freshness within 30 days to avoid false positives. Hunting hypotheses must be scoped to the environment before execution.
Threat Signal Analyzer
The threat_signal_analyzer.py tool supports three modes: hunt (hypothesis scoring), ioc (sweep generation), and anomaly (statistical detection).
bash
# Hunt mode: score a hypothesis against MITRE ATT&CK coverage
python3 scripts/threat_signal_analyzer.py --mode hunt \
--hypothesis "Lateral movement via PtH using compromised service account" \
--actor-relevance 3 --control-gap 2 --data-availability 2 --json
# IOC mode: generate sweep targets from an IOC feed file
python3 scripts/threat_signal_analyzer.py --mode ioc \
--ioc-file iocs.json --json
# Anomaly mode: detect statistical outliers in telemetry events
python3 scripts/threat_signal_analyzer.py --mode anomaly \
--events-file telemetry.json \
--baseline-mean 100 --baseline-std 25 --json
# List all supported MITRE ATT&CK techniques
python3 scripts/threat_signal_analyzer.py --list-techniques
WMI process spawned from WINRM, unusual parent-child chain
LOLBin execution for defense evasion
T1218
Process creation, command-line args
certutil.exe, regsvr32.exe, mshta.exe with network activity
Beaconing C2 via jitter-heavy intervals
T1071.001
Proxy logs, DNS logs
Regular interval outbound connections ±10% jitter
Pass-the-Hash lateral movement
T1550.002
Windows security event 4624 type 3
NTLM auth from unexpected source host to admin share
LSASS memory access
T1003.001
EDR memory access events
OpenProcess on lsass.exe from non-system process
Kerberoasting
T1558.003
Windows event 4769
High volume TGS requests for service accounts
Scheduled task persistence
T1053.005
Sysmon Event 1/11, Windows 4698
Scheduled task created in non-standard directory
IOC Analysis
IOC analysis determines whether indicators are fresh, maps them to required sweep targets, and filters stale data that generates false positives.
IOC Types and Sweep Priority
IOC Type
Staleness Threshold
Sweep Target
MITRE Coverage
IP addresses
30 days
Firewall logs, NetFlow, proxy logs
T1071, T1105
Domains
30 days
DNS resolver logs, proxy logs
T1568, T1583
File hashes
90 days
EDR file creation, AV scan logs
T1105, T1027
URLs
14 days
Proxy access logs, browser history
T1566.002
Mutex names
180 days
EDR runtime artifacts
T1055
IOC Staleness Handling
IOCs older than their threshold are flagged as stale and excluded from sweep target generation. Running sweeps against stale IOCs inflates false positive rates and reduces SOC credibility. Refresh IOC feeds from threat intelligence platforms (MISP, OpenCTI, commercial TI) before every hunt cycle.
Anomaly Detection
Statistical anomaly detection identifies behavior that deviates from established baselines without relying on known-bad signatures.
Z-Score Thresholds
Z-Score
Classification
Response
< 2.0
Normal
No action required
2.0–2.9
Soft anomaly
Log and monitor — increase sampling
≥ 3.0
Hard anomaly
Escalate to hunt analyst — investigate entity
Baseline Requirements
Effective anomaly detection requires at least 14 days of historical telemetry to establish a valid baseline. Baselines must be recomputed after:
Deception assets generate high-fidelity alerts — any interaction with a honeypot is an unambiguous signal requiring investigation.
Deception Asset Types and Placement
Asset Type
Placement
Signal
ATT&CK Technique
Honeypot credentials in password vault
Vault secrets store
Credential access attempt
T1555
Honey tokens (fake AWS access keys)
Git repos, S3 objects
Reconnaissance or exfiltration
T1552.004
Honey files (named: passwords.xlsx)
File shares, endpoints
Collection staging
T1074
Honey accounts (dormant AD users)
Active Directory
Lateral movement pivot
T1078.002
Honeypot network services
DMZ, flat network segments
Network scanning, service exploitation
T1046, T1190
Honeypot alerts bypass the standard scoring pipeline — any hit is an automatic SEV2 until proven otherwise.
Workflows
Workflow 1: Quick Hunt (30 Minutes)
For responding to a new threat intelligence report or CVE alert:
bash
# 1. Score hypothesis against environment context
python3 scripts/threat_signal_analyzer.py --mode hunt \
--hypothesis "Exploitation of CVE-YYYY-NNNNN in Apache" \
--actor-relevance 2 --control-gap 3 --data-availability 2 --json
# 2. Build IOC sweep list from threat intel
echo '{"ips": ["1.2.3.4"], "domains": ["malicious.tld"], "hashes": []}' > iocs.json
python3 scripts/threat_signal_analyzer.py --mode ioc --ioc-file iocs.json --json
# 3. Check for anomalies in web server telemetry from last 24h
python3 scripts/threat_signal_analyzer.py --mode anomaly \
--events-file web_events_24h.json --baseline-mean 80 --baseline-std 20 --json
Decision: If hunt priority ≥ 7 or any IOC sweep hits, escalate to full hunt.
Workflow 2: Full Threat Hunt (Multi-Day)
Day 1 — Hypothesis Generation:
Review threat intelligence feeds for sector-relevant TTPs
Map last 30 days of security alerts to ATT&CK tactics to identify gaps
Score top 5 hypotheses with threat_signal_analyzer.py hunt mode
Prioritize by score — start with highest
Day 2 — Data Collection and Query Execution:
Pull relevant telemetry from SIEM (date range: last 14 days)
Run anomaly detection across entity baselines
Execute IOC sweeps for all feeds fresh within 30 days
Review hunt playbooks in references/hunt-playbooks.md
Day 3 — Triage and Reporting:
Triage all anomaly findings — confirm or dismiss
Escalate confirmed activity to incident-response
Document new detection rules from hunt findings
Submit false-positive IOCs back to TI provider
Workflow 3: Continuous Monitoring (Automated)
Configure recurring anomaly detection against key entity baselines on a 6-hour cadence:
bash
# Run as cron job every 6 hours — auto-escalate on exit code 2
python3 scripts/threat_signal_analyzer.py --mode anomaly \
--events-file /var/log/telemetry/events_6h.json \
--baseline-mean "${BASELINE_MEAN}" \
--baseline-std "${BASELINE_STD}" \
--json > /var/log/threat-detection/$(date +%Y%m%d_%H%M%S).json
# Alert on exit code 2 (hard anomaly)
if [ $? -eq 2 ]; then
send_alert "Hard anomaly detected — threat_signal_analyzer"
fi
Anti-Patterns
Hunting without a hypothesis — Running broad queries across all telemetry without a focused question generates noise, not signal. Every hunt must start with a testable hypothesis scoped to one or two ATT&CK techniques.
Using stale IOCs — IOCs older than 30 days generate false positives that train analysts to ignore alerts. Always check IOC freshness before sweeping; exclude stale indicators from automated sweeps.
Skipping baseline establishment — Anomaly detection without a valid baseline produces alerts on normal high-volume days. Require 14+ days of baseline data before enabling statistical alerting on any entity type.
Hunting only known techniques — Hunting exclusively against documented ATT&CK techniques misses novel adversary behavior. Regularly include open-ended anomaly analysis that can surface unknown TTPs.
Not closing the feedback loop to detection engineering — Hunt findings that confirm malicious behavior must produce new detection rules. Hunting that doesn't improve detection coverage has no lasting value.
Treating every anomaly as a confirmed threat — High z-scores indicate deviation from baseline, not confirmed malice. All anomalies require human triage to confirm or dismiss before escalation.
Ignoring honeypot alerts — Any interaction with a deception asset is a high-fidelity signal. Treating honeypot alerts as noise invalidates the entire deception investment.
Threat Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Threat Detection compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Threat Detection this skillalirezarezvani/claude-skills
Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for high-throughput, protocol-aware traffic inspection (HTTP, TLS, DNS, SMB) and SIEM…
Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.
Industrial AI literature research with mandatory intake questions, venue-aware source prioritization, structured report outputs, and survey draft generation.
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.
Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.
A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Threat Detection is an agent skill from alirezarezvani/claude-skills. Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
When should I use Threat Detection?
Threat Detection fits situations like: hunting for threats in an environment; detecting behavioral anomalies in telemetry.
How do I install Threat Detection in Claude Code?
Run `npx skills add alirezarezvani/claude-skills --skill threat-detection -a claude-code`. Or copy the skill folder (engineering-team/skills/threat-detection in alirezarezvani/claude-skills) into .claude/skills/threat-detection in your project. Claude Code loads it when a task matches its description.
How do I install Threat Detection in Codex?
Run `npx skills add alirezarezvani/claude-skills --skill threat-detection -a codex`. Or copy the skill folder (engineering-team/skills/threat-detection in alirezarezvani/claude-skills) into .agents/skills/threat-detection in your project. Codex loads it when a task matches its description.
Can I use Threat Detection in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill threat-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-detection, .gemini/skills/threat-detection, .github/skills/threat-detection and .opencode/skills/threat-detection in your project.
What does Threat Detection need to run?
Going by SKILL.md and its folder, Threat Detection needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.
Does Threat Detection access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Threat Detection safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Threat Detection use?
Threat Detection is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Threat Detection use?
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.
What are the alternatives to Threat Detection?
Skills that share tags, products or a category with Threat Detection: Configuring Suricata For Network Monitoring (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mapping Mitre Attack Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Security Logs With Splunk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Industrial AI Research (brycewang-stanford/Auto-Empirical-Research-Skills, 4.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Threat Detection?
alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.
Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.