Agent skill

Threat Hunt Blueprint Assembly

by OTRF in OTRF/ThreatHunter-Playbook

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

MITAuto-check passedSecurity

Install Threat Hunt Blueprint Assembly

skills CLI
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-blueprint-generation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OTRF/ThreatHunter-Playbook hunt-blueprint-generation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-blueprint-generation .claude/skills/hunt-blueprint-generation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-blueprint-generation
GitHub stars
4.7k
Token cost
~1.2k tokens
SKILL.md length
559 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

  • Works in 4 steps: Normalize Blueprint Inputs → Assemble Blueprint Content → Refine Blueprint Content (In-Memory) → …
  • Packaging finished hunt planning outputs into one blueprint
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Producing an execution-ready threat hunt plan from a hypothesis and analytics

What it does

The skill packages the hunt planning trajectory into one structured plan, and runs only after research on system internals and adversary tradecraft, a structured hunt hypothesis, candidate data sources and generated analytics are finished. It is synthesis only: it preserves and organizes what earlier steps produced and must not add research, web searches, assumptions or new detection logic.

Three ordered steps are defined. First, normalize inputs by confirming the research summary, abuse patterns, hypothesis, data source summary and analytics details are present and asking for any missing one. Second, fill the sections of `references/hunt-blueprint-template.md` in order, keeping the original wording where possible and noting assumptions and gaps. Third, refine the text in memory for clarity and readability only, before anything is written to disk. Reference documents are read only when a step says so.

When your agent uses it

  • Packaging finished hunt planning outputs into one blueprint
  • Producing an execution-ready threat hunt plan from a hypothesis and analytics
  • Checking that all planning artifacts are present before a hunt starts

Example prompts

  • “Assemble the hunt blueprint from the hypothesis, data sources and analytics we produced earlier.”
  • “Use the blueprint template to package this hunt plan without adding any new analytics.”
  • “Which planning artifacts are still missing before we can write the blueprint?”

Requirements

  • Outputs from the earlier hunt planning skills

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Normalize Blueprint Inputs
  2. Assemble Blueprint Content
  3. Refine Blueprint Content (In-Memory)
  4. Validate and Write Blueprint

What it can do on your machine

Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Hunt Blueprint Assembly loads about 1.2k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 559 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 559 words, ~1,196 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-blueprint-generation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hunt-blueprint-generation
description
Assemble a complete hunt blueprint by consolidating outputs from prior hunt planning skills into a single, structured plan for execution. Use this skill after system and tradecraft research, hunt focus definition, data source identification, and analytics generation have been completed. This skill is synthesis and packaging only and must not introduce new research, assumptions, or analytics.
metadata.short-description
Generate a structured hunt blueprint for execution

Generate Hunt Blueprint

This skill produces a single, structured hunt blueprint that captures the full hunt planning trajectory in an execution-ready format.

It is executed after the following have been completed:

  • System internals and adversary tradecraft research
  • Hunt focus definition (structured hypothesis)
  • Candidate data source identification
  • Analytics generation

This skill is assembly and synthesis only. It preserves and organizes outputs from prior steps without adding new research, new evidence, or new analytic logic.

Workflow

  • You MUST complete each step in order and MUST NOT proceed until the current step is complete.
  • You MUST NOT read reference documents unless the current step explicitly instructs you to do so.
  • You MUST NOT perform new web searches or introduce new research.
  • You MUST NOT generate new analytics, detections, thresholds, or validation logic.
  • You MUST only use planning artifacts produced by prior skills.
Step 1: Normalize Blueprint Inputs

Confirm that all required inputs are available to assemble the hunt blueprint.

Use available planning artifacts, which may include:

  • Research summary (system internals and adversary tradecraft)
  • Candidate abuse patterns
  • Structured hunt hypothesis
  • Candidate data source summary
  • Analytics summary and per-analytic details

If any critical planning artifact is missing, request it before proceeding.

Do NOT read reference documents during this step.

This step is complete when all required inputs are available.

Step 2: Assemble Blueprint Content

Populate the hunt blueprint using the section structure and ordering defined in references/hunt-blueprint-template.md.

  • Preserve wording and intent from prior artifacts where possible.
  • Summarize only to reduce redundancy and improve readability.
  • Ensure consistency across:
    • Hunt hypothesis and research context
    • Research context and analytics intent
    • Candidate data sources and schema grounding
  • Explicitly capture assumptions, gaps, and planning notes.

Do NOT introduce new material or reinterpret prior outputs.

This step is complete when all blueprint sections are populated according to the template.

Show full SKILL.md (261 more words)Show less
Step 3: Refine Blueprint Content (In-Memory)

Refine the assembled blueprint for clarity and readability without writing it to disk yet.

Focus on editorial improvements only:

  • Improve wording for clarity and conciseness
  • Normalize terminology across hypothesis, research, data sources, and analytics
  • Ensure behavioral models are expressed using clear, graph-like statements
    (entity → relationship → entity)
  • Improve table readability and layout where needed

You MAY:

  • Rephrase sentences for clarity
  • Improve behavioral model descriptions
  • Adjust Markdown structure for readability

You MUST NOT:

  • Add or remove sections
  • Change analytic intent or behavioral logic
  • Introduce new research, assumptions, or analytics
  • Write the blueprint to disk

This step is complete when the blueprint reads clearly and consistently.

Step 4: Validate and Write Blueprint

Validate the refined blueprint and correct issues before writing the final file.

Confirm that:

  • The hunt hypothesis aligns with research context and the selected attack pattern
  • Candidate data sources plausibly support the modeled behaviors
  • Each analytic consistently connects:
    • Analytic intent
    • Data sources
    • Entities and behavioral model
    • Schema grounding
    • SQL-like query-style representation
  • Behavioral models are readable and graph-like
  • Markdown renders correctly with no formatting or encoding issues
  • Assumptions and gaps are planning-level only

You MAY:

  • Fix Markdown rendering issues (broken tables, malformed lists, encoding artifacts)
  • Correct structural violations of the template

You MUST NOT:

  • Reword content for clarity
  • Change analytic reasoning or behavior models
  • Introduce new research, assumptions, analytics, or execution logic

Once validated, write the blueprint to a Markdown file named after the hunt using lowercase words separated by underscores
(for example, windows_registry_persistence_hunt.md).

This step is complete when the blueprint is written and ready for execution.

© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .github/skills/hunt-blueprint-generation of OTRF/ThreatHunter-Playbook.

  • SKILL.md
  • references/hunt-blueprint-template.md

Open the folder on GitHubat commit d310f38

Compare with similar skills

Threat Hunt Blueprint Assembly next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Hunt Blueprint Assembly compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Hunt Blueprint Assembly this skillOTRF/ThreatHunter-Playbook4.7k—~1.2kAutomated safety check: PassMIT
Create Sigma RuleTracecatHQ/tracecat3.8k—~16kAutomated safety check: PassMIT
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Campaign Attribution Evidence Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Create Sigma Rule

    TracecatHQ/tracecat

    Turns a threat report, a malware analysis, vendor tool documentation, or a raw log sample into draft Sigma detection rules, validated against sigma-cli where a shell exists and labelled "not…

    3.8k GitHub stars~16k tokensUpdated today
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    115 GitHub stars~15k tokensUpdated 12 days ago
    SecurityAuto-check: notes

More from OTRF/ThreatHunter-Playbook

  • Hunt Data Source Identification

    OTRF/ThreatHunter-Playbook

    Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

    4.7k GitHub stars~813 tokensUpdated 9 mo ago
    Auto-check passed
  • Hunt Focus Definition

    OTRF/ThreatHunter-Playbook

    Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

    4.7k GitHub stars~600 tokensUpdated 9 mo ago
    Auto-check passed
  • Threat Hunt Research Grounding

    OTRF/ThreatHunter-Playbook

    Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

    4.7k GitHub stars~1.3k tokensUpdated 9 mo ago
    Auto-check passed
  • Hunt Analytics Generation

    OTRF/ThreatHunter-Playbook

    Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

    4.7k GitHub stars~819 tokensUpdated 9 mo ago
    Auto-check passed

Categories

Questions about Threat Hunt Blueprint Assembly

What does Threat Hunt Blueprint Assembly do?

Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics. The skill packages the hunt planning trajectory into one structured plan, and runs only after research on system internals and adversary tradecraft, a structured hunt hypothesis, candidate data sources and generated analytics are finished. It is synthesis only: it preserves and organizes what earlier steps produced and must not add research, web searches, assumptions or new detection logic.

When should I use Threat Hunt Blueprint Assembly?

Threat Hunt Blueprint Assembly fits situations like: packaging finished hunt planning outputs into one blueprint; producing an execution-ready threat hunt plan from a hypothesis and analytics; checking that all planning artifacts are present before a hunt starts.

How do I install Threat Hunt Blueprint Assembly in Claude Code?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-blueprint-generation -a claude-code`. Or copy the skill folder (.github/skills/hunt-blueprint-generation in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-blueprint-generation in your project. Claude Code loads it when a task matches its description.

How do I install Threat Hunt Blueprint Assembly in Codex?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-blueprint-generation -a codex`. Or copy the skill folder (.github/skills/hunt-blueprint-generation in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-blueprint-generation in your project. Codex loads it when a task matches its description.

Can I use Threat Hunt Blueprint Assembly in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-blueprint-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-blueprint-generation, .gemini/skills/hunt-blueprint-generation, .github/skills/hunt-blueprint-generation and .opencode/skills/hunt-blueprint-generation in your project.

What does Threat Hunt Blueprint Assembly need to run?

SKILL.md names no scripts, command-line tools or credentials: Threat Hunt Blueprint Assembly is instructions for the agent only. Our summary lists: Outputs from the earlier hunt planning skills.

Does Threat Hunt Blueprint Assembly access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Hunt Blueprint Assembly safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Threat Hunt Blueprint Assembly use?

Threat Hunt Blueprint Assembly is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Hunt Blueprint Assembly use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Threat Hunt Blueprint Assembly?

Skills that share tags, products or a category with Threat Hunt Blueprint Assembly: Create Sigma Rule (TracecatHQ/tracecat, 3.8k stars), Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars) and Security Detection Rule Management (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Hunt Blueprint Assembly?

OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.

Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.