Agent skill

Threat Hunting

by hypnguyen1209 in hypnguyen1209/offensive-claude

A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…

MITAuto-check passedSecurity

Install Threat Hunting

skills CLI
$ npx skills add hypnguyen1209/offensive-claude --skill threat-hunting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hypnguyen1209/offensive-claude threat-hunting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/threat-hunting .claude/skills/threat-hunting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-hunting
GitHub stars
388
Token cost
~2.4k tokens
SKILL.md length
600 words
Files
15 (incl. scripts, references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…

  • Hunting threats
  • SKILL.md covers When to Activate, Technique Map, Quick Start and OPSEC & Detection (summary), plus 1 more section
  • Runs Python and Shell scripts from its folder; calls python3
  • Engineering detections — ATT&CK Detection-Strategies

What it does

Threat Hunting is an agent skill from hypnguyen1209/offensive-claude. Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts and reference files (for example `references/cloud-identity-hunting.md`, `references/methodology-hunt-loop.md` and `references/network-c2-hunting.md`).

It sits in Security, covering Security operations and Red teaming and adversary simulation. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.

When your agent uses it

  • Hunting threats
  • Engineering detections — ATT&CK Detection-Strategies
  • Sigma + correlation with Detection-as-Code CI
  • Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins)

Example prompts

  • “/threat-hunting”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Hunting loads about 2.4k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 600 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 600 words, ~2,352 tokens.

Download SKILL.mdSave it as .claude/skills/threat-hunting/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
threat-hunting
description
Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation
metadata.type
defensive
metadata.phase
detection
metadata.tools
sigma-cli, pysigma, hayabusa, chainsaw, velociraptor, sysmon, zeek, rita, ja4, atomic-red-team, caldera, splunk, sentinel, defender, kql
metadata.mitre
TA0043
kill_chain.phase
report
kill_chain.step
8
kill_chain.attck_tactics
TA0043, TA0042, TA0011, TA0006, TA0005
kill_chain.attck_techniques
T1059.001, T1003.001, T1562.001, T1562.002, T1218, T1105, T1071, T1071.001, T1071.004, T1571, T1572, T1528, T1550.001, T1078.004, T1098, T1543.003, T1070.001…
depends_on
red-team-ops, incident-response
inputs
finding_records, log_data, ioc_list, evtx, zeek_logs, cloudtrail, sigin_logs

Threat Hunting & Detection Engineering

When to Activate

  • Hypothesis-driven hunting across endpoint, network, cloud, and identity telemetry
  • Writing & shipping detections (Sigma + correlation) as version-controlled code in CI
  • Mapping & measuring coverage against MITRE ATT&CK v18 (Detection Strategies / Analytics)
  • Hunting Windows post-exploitation: ETW/AMSI tampering, LSASS dumping, LOLBins, injection
  • Hunting C2 in encrypted traffic: JA4+/JA4X fingerprints, beaconing, DNS tunneling
  • Hunting cloud-identity attacks: Entra device-code/OAuth phishing, PRT theft, CloudTrail abuse
  • Purple-team validation: emulate ATT&CK with Atomic Red Team/Caldera, find detection gaps
  • Triaging EVTX/Zeek/CloudTrail offline during IR without a SIEM

Technique Map

TechniqueATT&CKCWEReferenceScript
Hypothesis-driven hunt loop (PEAK/TaHiTI)TA0043CWE-778references/methodology-hunt-loop.md-
ATT&CK v18 Detection-Strategies / Analytics mappingTA0043CWE-778references/methodology-hunt-loop.mdscripts/coverage_matrix.py
Detection-as-Code CI (lint + compile)TA0043CWE-778references/methodology-hunt-loop.mdscripts/dac_validate.py
Sysmon 15 PPL + tamper/visibility-gapT1562.001CWE-693references/windows-endpoint-hunting.mdscripts/sysmon_config_2025.xml
ETW / AMSI in-memory patch detectionT1562.001, T1562.002CWE-693references/windows-endpoint-hunting.mdscripts/evtx_hunt.py
LSASS credential-access handle huntT1003.001CWE-522references/windows-endpoint-hunting.mdscripts/evtx_hunt.py
LOLBin / process-tree anomaly huntT1218, T1105, T1059CWE-78references/windows-endpoint-hunting.mdscripts/evtx_hunt.py
Sigma rule + correlation engineeringTA0043CWE-778references/sigma-rule-engineering.mdscripts/dac_validate.py
EVTX triage (Hayabusa/Chainsaw/Velociraptor)TA0043CWE-778references/sigma-rule-engineering.mdscripts/sigma_pipeline.sh
JA4+/JA4X C2 fingerprintingT1071.001CWE-300references/network-c2-hunting.mdscripts/beacon_hunter.py
Beaconing / long-conn / prevalence (RITA-style)T1071, T1571CWE-940references/network-c2-hunting.mdscripts/beacon_hunter.py
DNS tunneling / DGA / DoH abuseT1071.004, T1572CWE-940references/network-c2-hunting.mdscripts/beacon_hunter.py
Entra device-code / OAuth consent phishingT1528, T1566CWE-287references/cloud-identity-hunting.mdscripts/entra_hunt.kql
PRT theft / token replayT1550.001CWE-522references/cloud-identity-hunting.mdscripts/entra_hunt.kql
AWS CloudTrail abuse / log tamperingT1078.004, T1098, T1562.008CWE-269references/cloud-identity-hunting.mdscripts/cloudtrail_hunt.py
Atomic Red Team / Caldera validationTA0043CWE-778references/purple-team-validation.mdscripts/coverage_matrix.py
Coverage matrix + ATT&CK Navigator + gap reportTA0043CWE-778references/purple-team-validation.mdscripts/coverage_matrix.py

Quick Start

bash
# 0. Deploy hunting telemetry baseline (Sysmon 15+, PPL self-protected)
sysmon -accepteula -i scripts/sysmon_config_2025.xml      # or: sysmon -c <file> to update

# 1. Offline endpoint triage over collected EVTX (no SIEM)
python3 scripts/evtx_hunt.py /cases/host01/EVTX --min-severity medium --json host01.json

# 2. Network: hunt C2 beacons / DNS tunneling over Zeek logs (+ optional JA4 blocklist)
zeek -r capture.pcap LogAscii::use_json=T
python3 scripts/beacon_hunter.py --conn conn.log --dns dns.log \
        --ja4-blocklist bad_ja4.txt --min-score 0.7

# 3. Cloud/identity: paste scripts/entra_hunt.kql into Sentinel/Defender;
#    triage AWS offline:
python3 scripts/cloudtrail_hunt.py /cases/cloudtrail/ --json ct_findings.json

# 4. Detection-as-Code: lint + compile your Sigma repo for CI (fail-fast)
python3 scripts/dac_validate.py rules/ --backend splunk --pipeline sysmon --fail-on-error
./scripts/sigma_pipeline.sh rules/ build/ splunk microsoft365defender elasticsearch

# 5. Purple-team validate + measure coverage (ATT&CK v18 Navigator layer + gaps)
Invoke-AtomicTest T1003.001 -TestNumbers 1,2,3   # lab only; -Cleanup after
python3 scripts/coverage_matrix.py --rules rules/ --atomic-results atomic_results.json \
        --watchlist watchlist.txt --navigator-out attack_layer.json --gaps-out gaps.csv

OPSEC & Detection (summary)

TechniqueTelemetry / IOCDetection (Sigma / EDR)OPSEC note
ETW/AMSI patchRWX in ntdll/amsi; ScriptBlock w/ AmsiScanBuffer+VirtualProtectSigma AMSI/ETW patch rule; Sysmon EID 25; ETW-TI (kernel)Userland patch defeats single source — correlate EID25 + ETW-TI + behavior
Sysmon killSystem 7036/7034, SysmonDrv unload, EPS drop to 0Visibility-gap metric on chatty hostsSysmon 15 is PPL; attacker kills agent instead — alert on stop/unload
LSASS dumpEID 10 handle to lsass + .dmp writeLSASS-access Sigma; access-mask + non-system sourceBaseline your own EDR/AV SourceImage set first or you flood the SOC
LOLBin abusecertutil/mshta/regsvr32 + http/decode/scrobjLOLBin Sigma; parent→child tree anomaliesHunt cold data first; live triage tips an EDR-aware operator
Beaconingperiodic intervals, uniform sizes, low prevalencebeacon_hunter.py CV<0.3; RITA; long-conn on non-interactive portNeed days of logs — small PCAPs inflate FPs
JA4X C2randomized certs sharing one JA4X (Sliver/Havoc)JA4 segment-pivot; JA4X blocklist at TLS-terminating proxyTLS 1.3 encrypts certs — capture at egress/proxy, don't block on FP alone
DNS tunnelinglong/high-entropy subdomains, TXT volume, NXDOMAIN spikesDNS entropy/volume scoring; DoH-to-public SigmaBaseline normal long-FQDN apps (CDNs) before alerting
Device-code phishdeviceCode sign-in, broker/OfficeHome AppId, new ASNentra_hunt.kql #1+#2; Elastic open rulesBaseline sanctioned device-code apps; not every device-code is evil
PRT theftprimaryRefreshToken from multi-geo same dayPRT KQL + LSASS/cloudAP endpoint joinControl-plane is the ONLY evidence — retain logs ≥90d before you need them
CloudTrail abuseStopLogging/DeleteTrail, CreateAccessKey for others, Describe* burstcloudtrail_hunt.py; Athena tamper queryAttackers disable logging early; enable org-wide all-region trail up front
Show full SKILL.md (113 more words)Show less

Deep Dives

  • references/methodology-hunt-loop.md — PEAK/TaHiTI hunt loop, ATT&CK v18 Detection Strategies (DETxxxx) & Analytics (ANxxxx) replacing legacy data sources, Detection-as-Code CI/CD (PTEFv4), visibility-gap detection.
  • references/windows-endpoint-hunting.md — Sysmon 15 PPL & tamper detection, ETW/AMSI in-memory patch detection (ETW-TI, EID 25, ScriptBlock), LSASS handle hunting, LOLBins & process-tree anomalies.
  • references/sigma-rule-engineering.md — Sigma rule anatomy, correlation rules (value_count/temporal), pySigma/sigma-cli compile, Hayabusa/Chainsaw/Velociraptor 0.74 native-Sigma EVTX triage, AI-assisted authoring (SigmaGen/Uncoder).
  • references/network-c2-hunting.md — JA4+/JA4S/JA4H/JA4X fingerprinting, Sliver/Havoc shared JA4X, RITA-style beaconing & long-connection stats, DNS tunneling/DGA/DoH, C2 framework signature cheat-sheet.
  • references/cloud-identity-hunting.md — Entra device-code phishing (STORM-2372, Tycoon2FA, EvilTokens), OAuth consent abuse, PRT theft, Graph enumeration, AWS CloudTrail abuse & tampering.
  • references/purple-team-validation.md — Atomic Red Team unit tests, MITRE Caldera chained emulation, ATT&CK v18-aware coverage matrix, Navigator layer generation, prioritized gap analysis.

© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (scripts, references) in skills/threat-hunting of hypnguyen1209/offensive-claude.

  • SKILL.md
  • references/cloud-identity-hunting.md
  • references/methodology-hunt-loop.md
  • references/network-c2-hunting.md
  • references/purple-team-validation.md
  • references/sigma-rule-engineering.md
  • references/windows-endpoint-hunting.md
  • scripts/beacon_hunter.py
  • scripts/cloudtrail_hunt.py
  • scripts/coverage_matrix.py
  • scripts/dac_validate.py
  • scripts/entra_hunt.kql
  • scripts/evtx_hunt.py
  • scripts/sigma_pipeline.sh
  • scripts/sysmon_config_2025.xml

Open the folder on GitHubat commit a506ad3

Compare with similar skills

Threat Hunting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Hunting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Hunting this skillhypnguyen1209/offensive-claude388—~2.4kAutomated safety check: PassMIT
Councilwarpdotdev/common-skills6101 repos~1.8kAutomated safety check: PassMIT
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Rational Red Blue Debatedigoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.0
Secops Investigategoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Council

    warpdotdev/common-skills

    Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

    610 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

    8.6k GitHub stars~2.2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Secops Investigate

    google/skills

    Official

    Expert guidance for deep security incident and entity investigations in Google SecOps.

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Pass The Hash Attacks

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from hypnguyen1209/offensive-claude

All 9 skills in this repo
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    388 GitHub stars~2.2k tokensUpdated 13 days ago
    Auto-check passed
  • Incident Response

    hypnguyen1209/offensive-claude

    A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

    388 GitHub stars~2.5k tokensUpdated 13 days ago
    Auto-check passed
  • Malware Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

    388 GitHub stars~2.3k tokensUpdated 13 days ago
    Auto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 13 days ago
    Auto-check passed
  • Threat Model Discipline

    hypnguyen1209/offensive-claude

    A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

    388 GitHub stars~660 tokensUpdated 13 days ago
    Auto-check passed
  • Writing Offensive Skills

    hypnguyen1209/offensive-claude

    A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…

    388 GitHub stars~826 tokensUpdated 13 days ago
    Auto-check passed

Categories

Questions about Threat Hunting

What does Threat Hunting do?

A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…. Threat Hunting is an agent skill from hypnguyen1209/offensive-claude.

When should I use Threat Hunting?

Threat Hunting fits situations like: hunting threats; engineering detections — ATT&CK Detection-Strategies; sigma + correlation with Detection-as-Code CI; windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins).

How do I install Threat Hunting in Claude Code?

Run `npx skills add hypnguyen1209/offensive-claude --skill threat-hunting -a claude-code`. Or copy the skill folder (skills/threat-hunting in hypnguyen1209/offensive-claude) into .claude/skills/threat-hunting in your project. Claude Code loads it when a task matches its description.

How do I install Threat Hunting in Codex?

Run `npx skills add hypnguyen1209/offensive-claude --skill threat-hunting -a codex`. Or copy the skill folder (skills/threat-hunting in hypnguyen1209/offensive-claude) into .agents/skills/threat-hunting in your project. Codex loads it when a task matches its description.

Can I use Threat Hunting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill threat-hunting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-hunting, .gemini/skills/threat-hunting, .github/skills/threat-hunting and .opencode/skills/threat-hunting in your project.

What does Threat Hunting need to run?

Going by SKILL.md and its folder, Threat Hunting needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; A Bash shell.

Does Threat Hunting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Hunting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Threat Hunting use?

Threat Hunting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Hunting use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Threat Hunting?

Skills that share tags, products or a category with Threat Hunting: Council (warpdotdev/common-skills, 610 stars), Cybersecurity (ohmyjahh/xquads-squads, 277 stars), Rational Red Blue Debate (digoal/blog, 8.6k stars) and Secops Investigate (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Hunting?

hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.

Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.