Agent skill

Threat Hunting

by briiirussell in briiirussell/cybersecurity-skills

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

MITAuto-check: notesSecurity

Install Threat Hunting

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills threat-hunting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/threat-hunting .claude/skills/threat-hunting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-hunting
GitHub stars
413
Token cost
~2.9k tokens
SKILL.md length
1,140 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

  • Works in 4 steps: Prepare → Execute → Act → …
  • The user mentions threat hunting
  • SKILL.md covers Methodology — PEAK framework, High-yield hunt catalog, Tools and Output Format, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Threat Hunting is an agent skill from briiirussell/cybersecurity-skills. Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. It works with PowerShell. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions threat hunting
  • MITRE ATT&CK hunt
  • Hypothesis-driven hunt
  • Hunt hypothesis

Example prompts

  • “threat hunting,”
  • “proactive hunt,”
  • “TaHiTI,”
  • “/threat-hunting”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, Glob, WebSearch

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Prepare
  2. Execute
  3. Act
  4. Knowledge

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are kql, spl and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Hunting loads about 2.9k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 1,140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,140 words, ~2,856 tokens.

Download SKILL.mdSave it as .claude/skills/threat-hunting/SKILL.md (or your agent's skills folder).
name
threat-hunting
description
Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.
allowed-tools
Read, Write, Bash, Grep, Glob, WebSearch

Threat Hunting — Proactive Adversary Detection

Hunt for adversaries who are already inside but haven't tripped an alert. Distinct from incident-triage (reactive, alert is firing) and from siem-detection (engineer rules so future alerts fire). This skill is the proactive layer — assume something has slipped through, look for it.

Hunting is hypothesis-driven, not browse-driven. "Let's look around the SIEM" is not hunting; "let's check for the specific pattern of T1059.001 (PowerShell) being launched by Office processes" is.

Cross-references: siem-detection (queries you write here often graduate to detection rules), incident-triage (what to do if a hunt confirms a finding), breach-patterns (a rich source of hunt hypotheses), disk-forensics (deeper analysis on confirmed hits).

Methodology — PEAK framework

The PEAK (Prepare, Execute, Act, Knowledge) framework from Splunk SURGe — the most actionable hunting methodology I've seen.

Step 1: Prepare

Form the hypothesis. Strong hypotheses share three properties:

  1. Specific — names a technique, log source, and expected artifact
  2. Testable — describes what evidence would confirm or deny
  3. Bounded — has a defined time window and scope

Bad hypothesis: "Look for anomalies in the SIEM" Good hypothesis: "Within the last 30 days, no service account should have run interactive PowerShell with -encodedCommand flag (T1059.001 + T1027). Search Sysmon event 1 for parent process = service-account-launched scheduled task, child = powershell.exe, command line contains -enc or -encodedcommand."

Hunt hypothesis sources, ranked by yield:

SourceYieldEffort
Recent incident (yours or peer's)HighLow — pattern is concrete
breach-patterns skill catalogHighLow — generalizes from public breaches
MITRE ATT&CK technique you don't have a detection forMediumMedium — read the technique, design the hunt
Threat intel report (CrowdStrike, Mandiant, vendor reports)MediumMedium — current patterns
Anomaly: "this number went up — why"LowLow — often FP, occasionally gold
Step 2: Execute

Run the hunt. Three execution patterns:

Pattern A — Pivot from indicator. Start with a specific IOC (IP, hash, domain) and look for any host or user that touched it.

kql
// Sentinel — pivot from a suspicious IP across all log sources
union *
| where TimeGenerated > ago(90d)
| where contains("198.51.100.42")
| project TimeGenerated, Type, Computer, _ResourceId

Pattern B — Pivot from technique. Start with an ATT&CK technique and look for any host doing that.

spl
// Splunk — T1547.001 Registry Run Keys persistence
index=sysmon EventCode=13 
  TargetObject="*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\*"
| stats values(Details) by Computer, User
| where len(values(Details)) > 1

Pattern C — Anomaly hunt. Establish a baseline; look for outliers.

kql
// Sentinel — service accounts authenticating from new geographies
SigninLogs
| where TimeGenerated > ago(30d)
| where UserType == "Service"
| summarize Countries = make_set(Location) by UserPrincipalName
| where array_length(Countries) > 1
Step 3: Act

For every hit, three possible outcomes:

OutcomeAction
Confirmed maliciousEscalate to incident-triage immediately
Confirmed benignDocument and move on
Unknown / unable to confirmDeepen investigation (host artifacts, network traffic, user interview)

Don't leave hits in the "unknown" state. Either resolve, or hand off with a documented next-step.

Step 4: Knowledge

The hunt's value isn't the one hit — it's the artifacts.

For each hunt:

  • If you found something, write a detection rule so future occurrences fire automatically (see siem-detection)
  • If you didn't find anything, document the hunt — query, scope, time window, conclusion. Future hunters won't re-do it
  • If the hunt was hard because of missing log coverage, document the gap and create a backlog item to fix log ingestion

Hunts that don't produce artifacts are work without compounding return. The whole point of the methodology is to turn every hunt into either a rule, a documented dead-end, or a coverage improvement.

High-yield hunt catalog

Persistence
  • Scheduled tasks created outside business hours — schtasks.exe /create from Sysmon event 1 + EventCode 4698 from Windows Security
  • Run-key persistence — registry writes to HKCU\...\Run, HKLM\...\Run, HKCU\...\RunOnce
  • Service installation outside known software-install windows — EventCode 7045
  • WMI persistence — __EventFilter and CommandLineEventConsumer subscriptions
  • Login items / launch daemons (macOS) — /Library/LaunchDaemons/*.plist, ~/Library/LaunchAgents/*.plist
  • Cron / systemd timers (Linux) — /etc/cron.*, /etc/systemd/system/*.timer, user crontabs
Defense evasion
  • PowerShell with -EncodedCommand — base64-encoded scripts are evasion 80% of the time
  • certutil.exe -decode — LOLBin used to decode dropper payloads
  • Sysmon EventCode 7 (Image loaded) for known-bad DLLs from non-standard paths
  • Process executing from %TEMP%, %APPDATA%, \Users\Public — non-standard exec paths
  • Command-line obfuscation patterns — large amounts of ^, backticks, cmd /c echo y | ...
Credential access
  • LSASS access from unexpected processes — Sysmon EventCode 10 with TargetImage = lsass.exe and SourceImage not in [mssense.exe, NisSrv.exe, ...]
  • procdump.exe or comsvcs.dll use — process-dumping LOLBins
  • NTDS.dit access outside backup windows — domain controller DB
  • AWS GetSessionToken or AssumeRole from new IPs — credential capture pivot
  • OAuth consent grants for high-scope applications — see iam-audit
Discovery
  • net group "Domain Admins" or equivalent enumeration commands
  • AD service ticket requests for high-value SPNs (Kerberoasting prep) — EventCode 4769 with RC4 encryption
  • whoami /all, quser, nltest /domain_trusts — situational awareness commands run by service accounts (humans rarely run these)
  • Cloud API listing — ListBuckets, ListUsers, DescribeInstances from unusual principals
Show full SKILL.md (436 more words)Show less
Lateral movement
  • WMI execution to remote hosts — Sysmon EventCode 1 with wmic.exe or Invoke-WmiMethod
  • PsExec / remote service creation patterns — EventCode 7045 with random service name
  • Remote registry connections to unusual hosts
  • SSH key reuse — one private key authenticating to many hosts in a short window
  • AWS / GCP AssumeRole chains across accounts — pivot detection
Collection / staging / exfil
  • Large-volume reads from cloud storage by single principal — unusual S3 / GCS access patterns
  • Archive creation patterns — Compress-Archive, 7z.exe, tar, zip operating on directories outside user home
  • DNS queries to recently-registered domains — exfil over DNS or C2 beacon resolution
  • Outbound TLS to high-risk geographies — depends on your organization's normal pattern
  • Beaconing patterns — regular-interval connections (every N seconds ± jitter) to the same destination over hours
Cloud-specific
  • IAM credential exfiltration patterns — GetCredentialReport, GenerateCredentialReport from unusual principals
  • IMDS access from unusual processes / containers — anything reaching 169.254.169.254 that isn't the cloud SDK
  • CloudTrail / Audit Log tampering attempts — StopLogging, DeleteTrail, log-bucket access from non-logging principals
  • Cross-region resource creation by single principal in short window — pivot or coin-mining setup
Identity-provider-specific
  • OAuth app grants of high-scope permissions (Google Workspace, M365) — adversary technique for persistence outside the user's password
  • MFA method enrollment from new device — attacker registering their own MFA after stealing a session
  • Sign-ins from impossible geographies — geolocation jumps that exceed travel time
  • Service-account authentication from new client / new IP — service accounts should be predictable

Tools

  • SIEM — Splunk, Sentinel, Elastic, Chronicle, Sumo, Wazuh
  • EDR — CrowdStrike (RTR), SentinelOne (deep visibility), Microsoft Defender (advanced hunting), Carbon Black
  • Sysmon — open-source endpoint logging on Windows, output to SIEM
  • osquery — SQL queries over endpoint state (cross-platform)
  • Velociraptor — open-source live response and hunting framework (much more capable than free EDR)
  • Zeek — network metadata for traffic analysis
  • MITRE ATT&CK Navigator — coverage visualization
  • Hunt-Evil — hunting playbook content (open-source)
  • MaxMind GeoIP — geolocation lookup for IP-based hunts

Output Format

markdown
# Threat Hunt Report
## Hunt name: [descriptive — e.g., "Office process → encoded PowerShell"]
## Hypothesis: [specific, testable, bounded]
## Date range: [from - to]
## Hunter: [name]

### Methodology
- ATT&CK technique(s): [TXXXX.NNN]
- Data sources queried: [list]
- Query / queries:
  [the actual SIEM query]

### Findings
| Hit ID | Host / User / Resource | Outcome | Notes |
|--------|------------------------|---------|-------|

### Conclusion
- [Confirmed malicious / All benign / Inconclusive]
- [Confidence level — Low / Medium / High]

### Artifacts produced
- [ ] Detection rule added (link)
- [ ] Coverage gap documented (link)
- [ ] Negative-result documentation filed (link)

### Recommended follow-up
[Anything that needs deeper investigation, escalation, or future hunts]

Boundaries

  • Hunt only environments the user has authorization for
  • Never query SIEM / EDR data outside the user's authority — even if the dataset is available, scope matters
  • For confirmed-malicious findings, escalate to incident-triage immediately — do not continue hunting and risk tipping the adversary
  • Live response actions (host isolation, account disablement) are incident response, not hunting — escalate
  • Refuse to use threat-hunting techniques to surveil employees beyond what HR / legal has authorized
  • Negative hunt results are valuable evidence, not failure — document and credit accordingly

References

  • PEAK Threat Hunting Framework (Splunk SURGe)
  • TaHiTI (Targeted Hunting integrating Threat Intelligence) — Dutch model
  • MITRE ATT&CK
  • "The ThreatHunter Playbook" (Cyb3rWard0g) — open-source content
  • Sigma rules repo — many rules can become hunt queries
  • "Practical Threat Intelligence and Data-Driven Threat Hunting" — Valentina Costa-Gazcón
  • David Bianco's "Pyramid of Pain" — IOC value hierarchy
  • SANS FOR508 / FOR578 course materials
  • Velociraptor community hunt content

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/threat-hunting of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Threat Hunting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Hunting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Hunting this skillbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: NotesMIT
Hunting For Shadow Copy Deletionmukul975/Anthropic-Cybersecurity-Skills34k—~891Automated safety check: PassApache-2.0
Hunting Evtx With Chainsawmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Hunting For Anomalous Powershell Executionmukul975/Anthropic-Cybersecurity-Skills34k—~638Automated safety check: PassApache-2.0
Windows Log Hunterptn1411/skill219—~1kAutomated safety check: NotesNone
Detecting Suspicious Powershell Executionmukul975/Anthropic-Cybersecurity-Skills34k—~923Automated safety check: PassApache-2.0

Similar skills

  • Hunting For Shadow Copy Deletion

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.

    34k GitHub stars~891 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting Evtx With Chainsaw

    mukul975/Anthropic-Cybersecurity-Skills

    Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting For Anomalous Powershell Execution

    mukul975/Anthropic-Cybersecurity-Skills

    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events.

    34k GitHub stars~638 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Windows Log Hunter

    ptn1411/skill

    Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill.

    219 GitHub stars~1k tokensUpdated 19 days ago
    SecurityAuto-check: notes
  • Detecting Suspicious Powershell Execution

    mukul975/Anthropic-Cybersecurity-Skills

    Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft…

    34k GitHub stars~923 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Purple Team Atomic Testing

    mukul975/Anthropic-Cybersecurity-Skills

    Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…

    34k GitHub stars~9.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Threat Hunting

What does Threat Hunting do?

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. Threat Hunting is an agent skill from briiirussell/cybersecurity-skills. Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

When should I use Threat Hunting?

Threat Hunting fits situations like: the user mentions threat hunting; MITRE ATT&CK hunt; hypothesis-driven hunt; hunt hypothesis.

How do I install Threat Hunting in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a claude-code`. Or copy the skill folder (skills/threat-hunting in briiirussell/cybersecurity-skills) into .claude/skills/threat-hunting in your project. Claude Code loads it when a task matches its description.

How do I install Threat Hunting in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a codex`. Or copy the skill folder (skills/threat-hunting in briiirussell/cybersecurity-skills) into .agents/skills/threat-hunting in your project. Codex loads it when a task matches its description.

Can I use Threat Hunting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-hunting, .gemini/skills/threat-hunting, .github/skills/threat-hunting and .opencode/skills/threat-hunting in your project.

What does Threat Hunting need to run?

SKILL.md names no scripts, command-line tools or credentials: Threat Hunting is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, WebSearch.

Does Threat Hunting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Hunting safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Threat Hunting use?

Threat Hunting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Hunting use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Threat Hunting?

Skills that share tags, products or a category with Threat Hunting: Hunting For Shadow Copy Deletion (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting Evtx With Chainsaw (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting For Anomalous Powershell Execution (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Windows Log Hunter (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Hunting?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.