Agent skill

Hunt Analytics Generation

by OTRF in OTRF/ThreatHunter-Playbook

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

MITAuto-check passedSecurity

Install Hunt Analytics Generation

skills CLI
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OTRF/ThreatHunter-Playbook hunt-analytics-generation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-analytics-generation .claude/skills/hunt-analytics-generation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-analytics-generation
GitHub stars
4.7k
Token cost
~819 tokens
SKILL.md length
379 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

  • Works in 3 steps: Interpret and Normalize Input → Generate Analytic Candidates (repeat up… → Produce Analytics Summary
  • Defining how a hunt hypothesis should show up in log data before writing queries
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Turning adversary tradecraft notes into analytics tied to real table schemas

What it does

This step belongs to hunt planning, after enough context exists and before any query is run or detection validated. It models behavior rather than deciding what is suspicious. The agent works through ordered steps and may not skip ahead, read reference documents unprompted, execute queries, validate results or add new research about system internals or adversary tradecraft. The first step normalizes the inputs, which may include system internals context, adversary tradecraft context, the structured hunt hypothesis and suggested data sources, and confirms which behavior is being modeled, asking for minimal clarification if needed.

The second step repeats up to five times. For each analytic candidate the agent selects data sources, retrieves schemas with the MS Sentinel search_tables tool, identifies entities such as process, user, host, registry key or IP, models the behavior as relationships or sequences between them, maps conditions to schema fields and records a SQL-like representation of intent without making it executable. The third step produces a summary, using references/analytic-template.md.

When your agent uses it

  • Defining how a hunt hypothesis should show up in log data before writing queries
  • Turning adversary tradecraft notes into analytics tied to real table schemas
  • Preparing analytic definitions to hand to a later query and validation step

Example prompts

  • “Generate analytics for the hypothesis that an adversary dumps credentials from LSASS, using the Sentinel tables.”
  • “Model how scheduled-task persistence should appear in process and registry data, without writing queries.”
  • “Turn this hunt focus into up to five analytic candidates grounded in the table schemas.”

Requirements

  • Access to table schemas through a platform tool such as the MS Sentinel search tool the skill names

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Interpret and Normalize Input
  2. Generate Analytic Candidates (repeat up to 5 times)
  3. Produce Analytics Summary

What it can do on your machine

Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Analytics Generation loads about 819 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 379 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~819
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 379 words, ~819 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-analytics-generation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hunt-analytics-generation
description
Generate query-agnostic analytics that model adversary behavior by translating hunt investigative intent into analytic definitions grounded in schema semantics. This skill is used to define how behavior should manifest in data before query execution or validation, and works best when informed by system internals, adversary tradecraft, a structured hunt focus, and suggested data sources.
metadata.short-description
Generate analytics for hunt planning

Generating Analytics

This skill translates hunt investigative intent into a small set of analytics that describe how adversary behavior should manifest in data.

It is executed during hunt planning, after sufficient context has been established, and before queries are executed or detections are validated.

This skill focuses on behavior modeling, not determining what is suspicious or anomalous, which requires broader environmental context beyond adversary descriptions or schema inspection.

Workflow

  • You MUST complete each step in order and MUST NOT proceed until the current step is complete.
  • You MUST NOT read reference documents unless the current step explicitly instructs you to do so.
  • You MUST NOT execute queries or validate results in this skill.
  • You MUST NOT introduce new research about system internals or adversary tradecraft.
  • You MAY retrieve table schemas using platform tools when explicitly instructed.
Step 1: Interpret and Normalize Input

Establish the context required to generate analytics.

  • Use the available inputs, which may include:
    • System internals context
    • Adversary tradecraft context
    • The structured hunt hypothesis
    • Suggested or identified data sources
  • Confirm the specific adversary behavior to be modeled.
  • If critical context is missing, request minimal clarification before proceeding.

This step is complete when the behavior to be modeled is clearly understood. Do NOT read reference documents during this step.

Show full SKILL.md (169 more words)Show less
Step 2: Generate Analytic Candidates (repeat up to 5 times)

For each analytic candidate:

  • Select the most relevant data source or sources from the available list.
  • Use MS Sentinel.search_tables to retrieve schema details for the selected tables.
  • Review schemas to understand available fields and attributes.
  • Identify the key entities involved (e.g., process, user, host, registry key, IP).
  • Model the behavior as relationships or sequences between entities, using a graph-like view to represent how the activity unfolds and the conditions that matter.
  • Ground the logic by mapping entities and conditions to schema fields.
  • Capture a query-style representation, using SQL-like logic, that expresses analytic intent without execution.

Do NOT determine whether the behavior is suspicious or anomalous. Do NOT write executable queries. Do NOT read reference documents during this step.

Step 3: Produce Analytics Summary

Produce a final summary of the generated analytics.

  • Structure the output using references/analytic-template.md.
  • Repeat the template for each analytic.
  • Clearly separate:
    • Behavioral reasoning
    • Schema grounding
    • Query-style representation

Do NOT include execution logic, thresholds, or validation steps.

© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .github/skills/hunt-analytics-generation of OTRF/ThreatHunter-Playbook.

  • SKILL.md
  • references/analytic-template.md

Open the folder on GitHubat commit d310f38

Compare with similar skills

Hunt Analytics Generation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Analytics Generation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Analytics Generation this skillOTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT
007sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT
Implementing Threat Modeling With Mitre Attackmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~5.6kAutomated safety check: PassMIT
X Raypashov/skills1.2k1 repos~10kAutomated safety check: PassMIT

Similar skills

  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed
  • Implementing Threat Modeling With Mitre Attack

    mukul975/Anthropic-Cybersecurity-Skills

    Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~5.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from OTRF/ThreatHunter-Playbook

  • Threat Hunt Blueprint Assembly

    OTRF/ThreatHunter-Playbook

    Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

    4.7k GitHub stars~1.2k tokensUpdated 8 mo ago
    Auto-check passed
  • Hunt Data Source Identification

    OTRF/ThreatHunter-Playbook

    Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

    4.7k GitHub stars~813 tokensUpdated 8 mo ago
    Auto-check passed
  • Hunt Focus Definition

    OTRF/ThreatHunter-Playbook

    Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

    4.7k GitHub stars~600 tokensUpdated 8 mo ago
    Auto-check passed
  • Threat Hunt Research Grounding

    OTRF/ThreatHunter-Playbook

    Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

    4.7k GitHub stars~1.3k tokensUpdated 8 mo ago
    Auto-check passed

Categories

Questions about Hunt Analytics Generation

What does Hunt Analytics Generation do?

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. This step belongs to hunt planning, after enough context exists and before any query is run or detection validated. It models behavior rather than deciding what is suspicious.

When should I use Hunt Analytics Generation?

Hunt Analytics Generation fits situations like: defining how a hunt hypothesis should show up in log data before writing queries; turning adversary tradecraft notes into analytics tied to real table schemas; preparing analytic definitions to hand to a later query and validation step.

How do I install Hunt Analytics Generation in Claude Code?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a claude-code`. Or copy the skill folder (.github/skills/hunt-analytics-generation in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-analytics-generation in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Analytics Generation in Codex?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a codex`. Or copy the skill folder (.github/skills/hunt-analytics-generation in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-analytics-generation in your project. Codex loads it when a task matches its description.

Can I use Hunt Analytics Generation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-analytics-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-analytics-generation, .gemini/skills/hunt-analytics-generation, .github/skills/hunt-analytics-generation and .opencode/skills/hunt-analytics-generation in your project.

What does Hunt Analytics Generation need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Analytics Generation is instructions for the agent only. Our summary lists: Access to table schemas through a platform tool such as the MS Sentinel search tool the skill names.

Does Hunt Analytics Generation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Analytics Generation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Analytics Generation use?

Hunt Analytics Generation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Analytics Generation use?

About 819 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 553 tokens, read only when the agent opens those files.

What are the alternatives to Hunt Analytics Generation?

Skills that share tags, products or a category with Hunt Analytics Generation: 007 (sickn33/agentic-awesome-skills, 47k stars), Implementing Threat Modeling With Mitre Attack (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security And Hardening (penpot/penpot, 61k stars) and Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Analytics Generation?

OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.

Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.