Agent skill

Hunt Credential Access

by dandye in dandye/ai-runbooks

Hunt for credential access techniques like LSASS dumping or browser credential theft.

Apache-2.0Auto-check: warningsSecurity

Install Hunt Credential Access

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add dandye/ai-runbooks --skill hunt-credential-access -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dandye/ai-runbooks hunt-credential-access --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dandye/ai-runbooks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-credential-access .claude/skills/hunt-credential-access && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-credential-access
GitHub stars
127
Token cost
~1.1k tokens
SKILL.md length
309 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Hunt for credential access techniques like LSASS dumping or browser credential theft.

  • Works in 7 steps: Research Techniques → Develop Hunt Queries → Execute Searches → …
  • Searching for evidence of credential harvesting
  • SKILL.md covers Inputs, Common Techniques, Workflow and Required Outputs, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hunt Credential Access is an agent skill from dandye/ai-runbooks. Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence of credential harvesting. Takes MITRE technique IDs and searches for behavioral indicators in SIEM.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. The licence is Apache-2.0.

When your agent uses it

  • Searching for evidence of credential harvesting
  • Tasks that involve Security operations

Example prompts

  • “/hunt-credential-access”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Research Techniques
  2. Develop Hunt Queries
  3. Execute Searches
  4. Analyze Results
  5. Enrich Findings
  6. Document Hunt
  7. Escalate or Conclude

What it can do on your machine

Read from SKILL.md and the folder at commit 72a6863. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are udm).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Credential Access loads about 1.1k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:74
    (target.file.full_path CONTAINS "Login Data" OR
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:76
    target.file.full_path CONTAINS "cookies.sqlite") AND

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dandye/ai-runbooks at commit 72a6863, republished under its Apache-2.0 licence (© dandye). 309 words, ~1,125 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-credential-access/SKILL.md (or your agent's skills folder).
name
hunt-credential-access
description
Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence of credential harvesting. Takes MITRE technique IDs and searches for behavioral indicators in SIEM.
type
Skill
required_roles.chronicle
roles/chronicle.editor
required_roles.gti
GTI Standard
personas
threat-hunter
generated.by
human:dandye
generated.at
2026-02-04T06:10:49-05:00

Credential Access TTP Hunt Skill

Proactively hunt for MITRE ATT&CK Credential Access techniques (T1003, T1555, etc.) based on threat intelligence or hypothesis.

Inputs

  • TECHNIQUE_IDS - Comma-separated MITRE technique IDs (e.g., "T1003.001,T1555.003")
  • TIME_FRAME_HOURS - Lookback period (default: 72)
  • (Optional) TARGET_SCOPE_QUERY - UDM query to narrow scope
  • (Optional) HUNT_HYPOTHESIS - Reason for the hunt
  • (Optional) HUNT_CASE_ID - SOAR case for tracking

Common Techniques

TechniqueDescription
T1003.001LSASS Memory
T1003.002Security Account Manager
T1003.003NTDS
T1003.004LSA Secrets
T1003.005Cached Domain Credentials
T1003.006DCSync
T1555.001Keychain
T1555.003Credentials from Web Browsers
T1555.004Windows Credential Manager

Workflow

Step 1: Research Techniques

For each technique in TECHNIQUE_IDS:

gti-mcp.get_threat_intel(query="Explain MITRE ATT&CK technique T1003.001")

Understand:

  • What the technique does
  • Common procedures/tools
  • Detection methods
Step 2: Develop Hunt Queries

T1003.001 - LSASS Memory Access:

udm
metadata.event_type = "PROCESS_LAUNCH" AND
target.process.file.full_path = "C:\\Windows\\System32\\lsass.exe"

Look for suspicious parent processes accessing lsass.exe.

T1003.001 - Known Dumping Tools:

udm
metadata.event_type = "PROCESS_LAUNCH" AND
(principal.process.command_line CONTAINS "mimikatz" OR
 principal.process.command_line CONTAINS "procdump" OR
 principal.process.command_line CONTAINS "sekurlsa")

T1555.003 - Browser Credential Files:

udm
metadata.event_type = "FILE_OPEN" AND
(target.file.full_path CONTAINS "Login Data" OR
 target.file.full_path CONTAINS "Web Data" OR
 target.file.full_path CONTAINS "cookies.sqlite") AND
principal.process.file.full_path NOT IN ("chrome.exe", "firefox.exe", "msedge.exe")

T1003.006 - DCSync:

udm
metadata.event_type = "DOMAIN_CONTROLLER_REPLICATION" AND
principal.hostname NOT IN @known_domain_controllers

General - Credential Dumping Tools:

udm
metadata.event_type = "PROCESS_LAUNCH" AND
(target.process.file.full_path CONTAINS "mimikatz" OR
 target.process.file.full_path CONTAINS "lazagne" OR
 target.process.file.full_path CONTAINS "pypykatz")

Combine with TARGET_SCOPE_QUERY if provided.

Step 3: Execute Searches
secops-mcp.search_security_events(text=query, hours_back=TIME_FRAME_HOURS)
Step 4: Analyze Results

Look for:

  • Low-prevalence events (unusual parent-child relationships)
  • Access from unexpected applications
  • Correlation with other suspicious activity
  • Known bad tool signatures
Step 5: Enrich Findings

If suspicious events found:

secops-mcp.lookup_entity(entity_value=USER_OR_HOST)

For file hashes:

gti-mcp.get_file_report(hash=HASH)
Step 6: Document Hunt

Use /document-in-case:

  • Techniques hunted with descriptions
  • Queries used
  • Findings (positive AND negative)
  • Enrichment results
  • Risk assessment
Step 7: Escalate or Conclude

Credential theft confirmed: → Trigger /respond-compromised-account for affected users → Escalate to incident response → Consider password resets for exposed credentials

No findings: → Document negative results → Confirm detection coverage for these techniques

Required Outputs

After completing this skill, you MUST report these outputs:

OutputDescription
FINDINGSDetected credential access activity (events, processes, files accessed)
DETECTED_TECHNIQUESMITRE techniques observed (e.g., T1003.001, T1555.003)
AFFECTED_ACCOUNTSAccounts potentially compromised (users whose credentials may be exposed)

Detection Gaps to Note

If queries return no results, consider:

  • Is the required telemetry being collected?
  • Are endpoint logs being forwarded to SIEM?
  • Do detection rules exist for these techniques?

Document gaps for security engineering follow-up.

© dandye, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-credential-access of dandye/ai-runbooks.

Open the folder on GitHubat commit 72a6863

Compare with similar skills

Hunt Credential Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Credential Access compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Credential Access this skilldandye/ai-runbooks127—~1.1kAutomated safety check: WarnApache-2.0
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
GatesNebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMIT

Similar skills

  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated yesterday
    SecurityAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from dandye/ai-runbooks

All 27 skills in this repo
  • Close Case Artifact

    dandye/ai-runbooks

    Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~615 tokensUpdated 1 mo ago
    Auto-check passed
  • Correlate Ioc

    dandye/ai-runbooks

    Check for existing SIEM alerts and case management entries related to IOCs.

    127 GitHub stars~624 tokensUpdated 1 mo ago
    Auto-check passed
  • Deep Dive Ioc

    dandye/ai-runbooks

    Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Enrich Ioc

    dandye/ai-runbooks

    Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

    127 GitHub stars~702 tokensUpdated 1 mo ago
    Auto-check passed
  • Find Relevant Case

    dandye/ai-runbooks

    Search for existing cases related to specific indicators or entities.

    127 GitHub stars~562 tokensUpdated 1 mo ago
    Auto-check passed
  • Full Alert Triage

    dandye/ai-runbooks

    Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt Credential Access

What does Hunt Credential Access do?

Hunt for credential access techniques like LSASS dumping or browser credential theft. Hunt Credential Access is an agent skill from dandye/ai-runbooks. Hunt for credential access techniques like LSASS dumping or browser credential theft.

When should I use Hunt Credential Access?

Hunt Credential Access fits situations like: searching for evidence of credential harvesting; tasks that involve Security operations.

How do I install Hunt Credential Access in Claude Code?

Run `npx skills add dandye/ai-runbooks --skill hunt-credential-access -a claude-code`. Or copy the skill folder (skills/hunt-credential-access in dandye/ai-runbooks) into .claude/skills/hunt-credential-access in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Credential Access in Codex?

Run `npx skills add dandye/ai-runbooks --skill hunt-credential-access -a codex`. Or copy the skill folder (skills/hunt-credential-access in dandye/ai-runbooks) into .agents/skills/hunt-credential-access in your project. Codex loads it when a task matches its description.

Can I use Hunt Credential Access in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dandye/ai-runbooks --skill hunt-credential-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-credential-access, .gemini/skills/hunt-credential-access, .github/skills/hunt-credential-access and .opencode/skills/hunt-credential-access in your project.

What does Hunt Credential Access need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Credential Access is instructions for the agent only.

Does Hunt Credential Access access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Credential Access safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hunt Credential Access use?

Hunt Credential Access is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Credential Access use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Credential Access?

Skills that share tags, products or a category with Hunt Credential Access: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Chaitin CLI (chaitin/chaitin-cli, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Credential Access?

dandye (a GitHub user) maintains it in dandye/ai-runbooks, which has 127 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 14, 2026.

Source: dandye/ai-runbooks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.