Agent skill

Hunt Threat

by dandye in dandye/ai-runbooks

Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks.

Apache-2.0Auto-check passedSecurity

Install Hunt Threat

skills CLI
$ npx skills add dandye/ai-runbooks --skill hunt-threat -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dandye/ai-runbooks hunt-threat --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dandye/ai-runbooks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-threat .claude/skills/hunt-threat && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-threat
GitHub stars
127
Token cost
~1.4k tokens
SKILL.md length
459 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks.

  • Works in 8 steps: Define Hypothesis & Scope → Deep Intelligence Analysis → Develop Initial Hunt Queries → …
  • Performing advanced hunting based on threat intelligence
  • SKILL.md covers Inputs, Workflow, Required Outputs and Hunt Hypothesis Templates, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hunt Threat is an agent skill from dandye/ai-runbooks. Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations and OSINT. The licence is Apache-2.0.

When your agent uses it

  • Performing advanced hunting based on threat intelligence
  • Tasks that involve Security operations
  • Tasks that involve OSINT

Example prompts

  • “/hunt-threat”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Define Hypothesis & Scope
  2. Deep Intelligence Analysis
  3. Develop Initial Hunt Queries
  4. Iterative Search & Analysis
  5. Advanced Enrichment
  6. Continuous Documentation
  7. Hunt Report
  8. Action Based on Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 72a6863. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are udm).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Threat loads about 1.4k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 459 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dandye/ai-runbooks at commit 72a6863, republished under its Apache-2.0 licence (© dandye). 459 words, ~1,408 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-threat/SKILL.md (or your agent's skills folder).
name
hunt-threat
description
Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation.
type
Skill
required_roles.chronicle
roles/chronicle.editor
required_roles.gti
GTI Enterprise
personas
threat-hunter, tier3-analyst
generated.by
human:dandye
generated.at
2026-02-04T06:10:49-05:00

Advanced Threat Hunting Skill

Conduct proactive, hypothesis-driven threat hunts based on threat intelligence, observed anomalies, or specific TTPs.

Inputs

  • HUNT_HYPOTHESIS - Clear statement of the hunt objective (required)
    • Example: "Suspected DNS tunneling for C2 based on recent actor TTPs"
    • Example: "Anomalous PowerShell execution on critical servers"
    • Example: "Living-off-the-land techniques bypassing EDR"
  • (Optional) RELEVANT_GTI_REPORTS - GTI Collection IDs or report names
  • (Optional) TARGET_SCOPE_QUERY - UDM query to narrow initial scope
  • TIME_FRAME_HOURS - Lookback period (default: 168 = 7 days)
  • (Optional) HUNT_CASE_ID - case for tracking the hunt

Workflow

Step 1: Define Hypothesis & Scope

Clearly articulate:

  • What threat behavior are we looking for?
  • What would evidence of this look like in logs?
  • What systems/users are in scope?
  • What time period is relevant?

Create or identify HUNT_CASE_ID for documentation.

Step 2: Deep Intelligence Analysis

For each relevant GTI report:

gti-mcp.get_collection_report(id=REPORT_ID)
gti-mcp.get_entities_related_to_a_collection(id=REPORT_ID, relationship_name="attack_techniques")
gti-mcp.get_collection_timeline_events(id=REPORT_ID)
gti-mcp.get_collection_mitre_tree(id=REPORT_ID)

Also:

gti-mcp.get_threat_intel(query="Details on specific TTPs")
Step 3: Develop Initial Hunt Queries

Based on hypothesis and intelligence, formulate advanced queries:

SIEM queries:

secops-mcp.search_security_events(
    text="Advanced UDM query targeting specific behaviors",
    hours_back=TIME_FRAME_HOURS
)

BigQuery (for large-scale analysis):

bigquery.execute-query(query="Complex analytical query")
Step 4: Iterative Search & Analysis

Hunt Loop:

  1. Execute queries
  2. Analyze results for outliers, suspicious patterns
  3. Identify leads (suspicious hosts, users, processes, connections)
  4. Refine hypothesis based on findings
  5. Develop new, more targeted queries
  6. Repeat until exhausted or time limit reached

Key questions at each iteration:

  • Does this match our hypothesis?
  • What's the baseline/normal behavior?
  • Are these true anomalies or noise?
  • What should we pivot on next?
Step 5: Advanced Enrichment

For each promising lead:

secops-mcp.lookup_entity(entity_value=LEAD)

GTI enrichment and pivoting:

gti-mcp.get_..._report(identifier=LEAD)
gti-mcp.get_entities_related_to_...(identifier=LEAD)

Check IOC matches:

secops-mcp.get_ioc_matches()
Step 6: Continuous Documentation

Document throughout in HUNT_CASE_ID:

  • Queries used (with results summary)
  • Analysis reasoning
  • Positive and negative findings
  • Pivots and why they were taken

Use /document-in-case for each significant finding.

Show full SKILL.md (191 more words)Show less
Step 7: Hunt Report

Use /generate-report with REPORT_TYPE="hunt_summary":

  • Hypothesis and scope
  • Intelligence sources used
  • Queries executed
  • Findings (positive and negative)
  • Recommendations
Step 8: Action Based on Findings

Confirmed Threat Found: → Escalate to Incident Response immediately → Create incident case, hand over evidence

Suspicious Activity (not confirmed): → Recommend enhanced monitoring → Propose new detection rules to Security Engineering

Valuable Insights (no active threat): → Document for future reference → Propose detection improvements

Inconclusive: → Document process and limitations → Note areas for future investigation

Required Outputs

After completing this skill, you MUST report these outputs:

OutputDescription
HUNT_QUERIESUDM queries executed during the hunt
INITIAL_FINDINGSRaw findings from SIEM searches
FINDINGS_TYPECategory: lateral_movement, credential_access, data_exfil, or generic
DISCOVERED_IOCSIOCs extracted from findings (IPs, domains, hashes)
HIGH_CONFIDENCE_IOCSIOCs confirmed malicious via GTI enrichment
THREAT_CONFIRMEDBoolean: true if active threat confirmed, false otherwise

Hunt Hypothesis Templates

TTP-Based:

"Hunt for [MITRE Technique] activity, specifically [observable behavior], targeting [scope] over [timeframe]."

Actor-Based:

"Hunt for [Threat Actor] TTPs including [specific techniques], focusing on [likely targets] based on [intelligence source]."

Anomaly-Based:

"Investigate anomalous [behavior type] observed in [data source], specifically [anomaly description], to determine if malicious."

Example Hunt Queries

DNS Tunneling:

udm
metadata.event_type = "NETWORK_DNS" AND
network.dns.questions.name MATCHES ".*[a-z0-9]{30,}.*" AND
target.hostname NOT IN @known_cdn_domains

Suspicious PowerShell:

udm
metadata.event_type = "PROCESS_LAUNCH" AND
target.process.file.full_path MATCHES ".*powershell.*" AND
target.process.command_line MATCHES ".*(encodedcommand|bypass|hidden).*"

Living-off-the-Land:

udm
metadata.event_type = "PROCESS_LAUNCH" AND
target.process.file.full_path IN @lolbins_list AND
principal.user.userid NOT IN @authorized_admins

© dandye, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-threat of dandye/ai-runbooks.

Open the folder on GitHubat commit 72a6863

Compare with similar skills

Hunt Threat next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Threat compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Threat this skilldandye/ai-runbooks127—~1.4kAutomated safety check: PassApache-2.0
Threat Intelligence OSINTzhaoxuya520/reverse-skill41k1 repos~1kAutomated safety check: PassMIT
Secops Detection Engineeringgoogle/skills21k1 repos~4.8kAutomated safety check: PassApache-2.0
Building Threat Hunt Hypothesis Frameworkmukul975/Anthropic-Cybersecurity-Skills34k—~893Automated safety check: PassApache-2.0
Implementing Stix Taxii Feed Integrationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Performing False Positive Reduction In Siemmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    41k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Official

    Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.

    21k GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check passed
  • Building Threat Hunt Hypothesis Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender…

    34k GitHub stars~893 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Stix Taxii Feed Integration

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and producer in Python, covering TAXII server discovery, collection polling, parsing STIX bundles with the stix2 library, and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing False Positive Reduction In Siem

    mukul975/Anthropic-Cybersecurity-Skills

    Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Indicator Lifecycle Management

    mukul975/Anthropic-Cybersecurity-Skills

    Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and…

    34k GitHub stars~1.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from dandye/ai-runbooks

All 27 skills in this repo
  • Close Case Artifact

    dandye/ai-runbooks

    Close a case or alert with proper reason and documentation. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~615 tokensUpdated 1 mo ago
    Auto-check passed
  • Correlate Ioc

    dandye/ai-runbooks

    Check for existing SIEM alerts and case management entries related to IOCs.

    127 GitHub stars~624 tokensUpdated 1 mo ago
    Auto-check passed
  • Deep Dive Ioc

    dandye/ai-runbooks

    Perform exhaustive analysis of a critical IOC. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Enrich Ioc

    dandye/ai-runbooks

    Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

    127 GitHub stars~702 tokensUpdated 1 mo ago
    Auto-check passed
  • Find Relevant Case

    dandye/ai-runbooks

    Search for existing cases related to specific indicators or entities.

    127 GitHub stars~562 tokensUpdated 1 mo ago
    Auto-check passed
  • Full Alert Triage

    dandye/ai-runbooks

    Complete Tier 1 triage workflow. An agent skill from dandye/ai-runbooks.

    127 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt Threat

What does Hunt Threat do?

Conduct proactive, hypothesis-driven threat hunting. An agent skill from dandye/ai-runbooks. Hunt Threat is an agent skill from dandye/ai-runbooks. Conduct proactive, hypothesis-driven threat hunting.

When should I use Hunt Threat?

Hunt Threat fits situations like: performing advanced hunting based on threat intelligence; tasks that involve Security operations; tasks that involve OSINT.

How do I install Hunt Threat in Claude Code?

Run `npx skills add dandye/ai-runbooks --skill hunt-threat -a claude-code`. Or copy the skill folder (skills/hunt-threat in dandye/ai-runbooks) into .claude/skills/hunt-threat in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Threat in Codex?

Run `npx skills add dandye/ai-runbooks --skill hunt-threat -a codex`. Or copy the skill folder (skills/hunt-threat in dandye/ai-runbooks) into .agents/skills/hunt-threat in your project. Codex loads it when a task matches its description.

Can I use Hunt Threat in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dandye/ai-runbooks --skill hunt-threat -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-threat, .gemini/skills/hunt-threat, .github/skills/hunt-threat and .opencode/skills/hunt-threat in your project.

What does Hunt Threat need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Threat is instructions for the agent only.

Does Hunt Threat access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Threat safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Threat use?

Hunt Threat is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Threat use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Threat?

Skills that share tags, products or a category with Hunt Threat: Threat Intelligence OSINT (zhaoxuya520/reverse-skill, 41k stars), Secops Detection Engineering (google/skills, 21k stars), Building Threat Hunt Hypothesis Framework (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Stix Taxii Feed Integration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Threat?

dandye (a GitHub user) maintains it in dandye/ai-runbooks, which has 127 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 14, 2026.

Source: dandye/ai-runbooks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.