007
sickn33/agentic-awesome-skills
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .claude/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .claude/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .agents/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .agents/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .cursor/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .cursor/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OTRF/ThreatHunter-Playbook.git --path .github/skills/hunt-analytics-generation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .gemini/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .gemini/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .github/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .github/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .opencode/skills/hunt-analytics-generation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-analytics-generation" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-analytics-generation into .opencode/skills/hunt-analytics-generation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-analytics-generation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-analytics-generationTranslates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.
This step belongs to hunt planning, after enough context exists and before any query is run or detection validated. It models behavior rather than deciding what is suspicious. The agent works through ordered steps and may not skip ahead, read reference documents unprompted, execute queries, validate results or add new research about system internals or adversary tradecraft. The first step normalizes the inputs, which may include system internals context, adversary tradecraft context, the structured hunt hypothesis and suggested data sources, and confirms which behavior is being modeled, asking for minimal clarification if needed.
The second step repeats up to five times. For each analytic candidate the agent selects data sources, retrieves schemas with the MS Sentinel search_tables tool, identifies entities such as process, user, host, registry key or IP, models the behavior as relationships or sequences between them, maps conditions to schema fields and records a SQL-like representation of intent without making it executable. The third step produces a summary, using references/analytic-template.md.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt Analytics Generation loads about 819 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 379 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 379 words, ~819 tokens.
.claude/skills/hunt-analytics-generation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.This skill translates hunt investigative intent into a small set of analytics that describe how adversary behavior should manifest in data.
It is executed during hunt planning, after sufficient context has been established, and before queries are executed or detections are validated.
This skill focuses on behavior modeling, not determining what is suspicious or anomalous, which requires broader environmental context beyond adversary descriptions or schema inspection.
Establish the context required to generate analytics.
This step is complete when the behavior to be modeled is clearly understood. Do NOT read reference documents during this step.
For each analytic candidate:
MS Sentinel.search_tables to retrieve schema details for the selected tables.Do NOT determine whether the behavior is suspicious or anomalous. Do NOT write executable queries. Do NOT read reference documents during this step.
Produce a final summary of the generated analytics.
references/analytic-template.md.Do NOT include execution logic, thresholds, or validation steps.
© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .github/skills/hunt-analytics-generation of OTRF/ThreatHunter-Playbook.
Open the folder on GitHubat commit d310f38
Hunt Analytics Generation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Analytics Generation this skillOTRF/ThreatHunter-Playbook | 4.7k | — | ~819 | Automated safety check: Pass | MIT | |
| 007sickn33/agentic-awesome-skills | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | |
| Implementing Threat Modeling With Mitre Attackmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~5.6k | Automated safety check: Pass | MIT | |
| X Raypashov/skills | 1.2k | 1 repos | ~10k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
mukul975/Anthropic-Cybersecurity-Skills
Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
pashov/skills
Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
OTRF/ThreatHunter-Playbook
Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.
OTRF/ThreatHunter-Playbook
Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.
OTRF/ThreatHunter-Playbook
Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.
OTRF/ThreatHunter-Playbook
Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.
Categories
Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. This step belongs to hunt planning, after enough context exists and before any query is run or detection validated. It models behavior rather than deciding what is suspicious.
Hunt Analytics Generation fits situations like: defining how a hunt hypothesis should show up in log data before writing queries; turning adversary tradecraft notes into analytics tied to real table schemas; preparing analytic definitions to hand to a later query and validation step.
Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a claude-code`. Or copy the skill folder (.github/skills/hunt-analytics-generation in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-analytics-generation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a codex`. Or copy the skill folder (.github/skills/hunt-analytics-generation in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-analytics-generation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-analytics-generation, .gemini/skills/hunt-analytics-generation, .github/skills/hunt-analytics-generation and .opencode/skills/hunt-analytics-generation in your project.
SKILL.md names no scripts, command-line tools or credentials: Hunt Analytics Generation is instructions for the agent only. Our summary lists: Access to table schemas through a platform tool such as the MS Sentinel search tool the skill names.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt Analytics Generation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 819 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 553 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hunt Analytics Generation: 007 (sickn33/agentic-awesome-skills, 47k stars), Implementing Threat Modeling With Mitre Attack (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security And Hardening (penpot/penpot, 61k stars) and Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.
Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.