Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .claude/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .agents/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .cursor/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .gemini/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .github/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "threat-hunting" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/threat-hunting into .opencode/skills/threat-hunting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-hunting", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
threat-hunting
GitHub stars
413
Token cost
~2.9k tokens
SKILL.md length
1,140 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT
At a glance
Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.
Works in 4 steps: Prepare → Execute → Act → …
The user mentions threat hunting
SKILL.md covers Methodology — PEAK framework, High-yield hunt catalog, Tools and Output Format, plus 2 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Threat Hunting is an agent skill from briiirussell/cybersecurity-skills. Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security operations. It works with PowerShell. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.
Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves these tools, so the agent can use them without asking each time:
Read
Write
Bash
Grep
Glob
WebSearch
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are kql, spl and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Threat Hunting loads about 2.9k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 1,140 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~131
When it runs· the whole SKILL.md, loaded when a task matches
~2.9k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/threat-hunting/SKILL.md (or your agent's skills folder).
name
threat-hunting
description
Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.
allowed-tools
Read, Write, Bash, Grep, Glob, WebSearch
Threat Hunting — Proactive Adversary Detection
Hunt for adversaries who are already inside but haven't tripped an alert. Distinct from incident-triage (reactive, alert is firing) and from siem-detection (engineer rules so future alerts fire). This skill is the proactive layer — assume something has slipped through, look for it.
Hunting is hypothesis-driven, not browse-driven. "Let's look around the SIEM" is not hunting; "let's check for the specific pattern of T1059.001 (PowerShell) being launched by Office processes" is.
Cross-references: siem-detection (queries you write here often graduate to detection rules), incident-triage (what to do if a hunt confirms a finding), breach-patterns (a rich source of hunt hypotheses), disk-forensics (deeper analysis on confirmed hits).
Methodology — PEAK framework
The PEAK (Prepare, Execute, Act, Knowledge) framework from Splunk SURGe — the most actionable hunting methodology I've seen.
Step 1: Prepare
Form the hypothesis. Strong hypotheses share three properties:
Specific — names a technique, log source, and expected artifact
Testable — describes what evidence would confirm or deny
Bounded — has a defined time window and scope
Bad hypothesis: "Look for anomalies in the SIEM"
Good hypothesis: "Within the last 30 days, no service account should have run interactive PowerShell with -encodedCommand flag (T1059.001 + T1027). Search Sysmon event 1 for parent process = service-account-launched scheduled task, child = powershell.exe, command line contains -enc or -encodedcommand."
Hunt hypothesis sources, ranked by yield:
Source
Yield
Effort
Recent incident (yours or peer's)
High
Low — pattern is concrete
breach-patterns skill catalog
High
Low — generalizes from public breaches
MITRE ATT&CK technique you don't have a detection for
Pattern A — Pivot from indicator. Start with a specific IOC (IP, hash, domain) and look for any host or user that touched it.
kql
// Sentinel — pivot from a suspicious IP across all log sources
union *
| where TimeGenerated > ago(90d)
| where contains("198.51.100.42")
| project TimeGenerated, Type, Computer, _ResourceId
Pattern B — Pivot from technique. Start with an ATT&CK technique and look for any host doing that.
spl
// Splunk — T1547.001 Registry Run Keys persistence
index=sysmon EventCode=13
TargetObject="*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\*"
| stats values(Details) by Computer, User
| where len(values(Details)) > 1
Pattern C — Anomaly hunt. Establish a baseline; look for outliers.
kql
// Sentinel — service accounts authenticating from new geographies
SigninLogs
| where TimeGenerated > ago(30d)
| where UserType == "Service"
| summarize Countries = make_set(Location) by UserPrincipalName
| where array_length(Countries) > 1
Step 3: Act
For every hit, three possible outcomes:
Outcome
Action
Confirmed malicious
Escalate to incident-triage immediately
Confirmed benign
Document and move on
Unknown / unable to confirm
Deepen investigation (host artifacts, network traffic, user interview)
Don't leave hits in the "unknown" state. Either resolve, or hand off with a documented next-step.
Step 4: Knowledge
The hunt's value isn't the one hit — it's the artifacts.
For each hunt:
If you found something, write a detection rule so future occurrences fire automatically (see siem-detection)
If you didn't find anything, document the hunt — query, scope, time window, conclusion. Future hunters won't re-do it
If the hunt was hard because of missing log coverage, document the gap and create a backlog item to fix log ingestion
Hunts that don't produce artifacts are work without compounding return. The whole point of the methodology is to turn every hunt into either a rule, a documented dead-end, or a coverage improvement.
High-yield hunt catalog
Persistence
Scheduled tasks created outside business hours — schtasks.exe /create from Sysmon event 1 + EventCode 4698 from Windows Security
Run-key persistence — registry writes to HKCU\...\Run, HKLM\...\Run, HKCU\...\RunOnce
Service installation outside known software-install windows — EventCode 7045
WMI persistence — __EventFilter and CommandLineEventConsumer subscriptions
Threat Hunting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Threat Hunting compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Threat Hunting this skillbriiirussell/cybersecurity-skills
Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.
Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log…
Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft…
Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. Threat Hunting is an agent skill from briiirussell/cybersecurity-skills. Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.
When should I use Threat Hunting?
Threat Hunting fits situations like: the user mentions threat hunting; MITRE ATT&CK hunt; hypothesis-driven hunt; hunt hypothesis.
How do I install Threat Hunting in Claude Code?
Run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a claude-code`. Or copy the skill folder (skills/threat-hunting in briiirussell/cybersecurity-skills) into .claude/skills/threat-hunting in your project. Claude Code loads it when a task matches its description.
How do I install Threat Hunting in Codex?
Run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a codex`. Or copy the skill folder (skills/threat-hunting in briiirussell/cybersecurity-skills) into .agents/skills/threat-hunting in your project. Codex loads it when a task matches its description.
Can I use Threat Hunting in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill threat-hunting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-hunting, .gemini/skills/threat-hunting, .github/skills/threat-hunting and .opencode/skills/threat-hunting in your project.
What does Threat Hunting need to run?
SKILL.md names no scripts, command-line tools or credentials: Threat Hunting is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, WebSearch.
Does Threat Hunting access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Threat Hunting safe to install?
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Threat Hunting use?
Threat Hunting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Threat Hunting use?
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Threat Hunting?
Skills that share tags, products or a category with Threat Hunting: Hunting For Shadow Copy Deletion (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting Evtx With Chainsaw (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting For Anomalous Powershell Execution (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Windows Log Hunter (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Threat Hunting?
briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.