Agent skill

Hunt Focus Definition

by OTRF in OTRF/ThreatHunter-Playbook

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

MITAuto-check passedSecurity

Install Hunt Focus Definition

skills CLI
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-focus-definition -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OTRF/ThreatHunter-Playbook hunt-focus-definition --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-focus-definition .claude/skills/hunt-focus-definition && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-focus-definition
GitHub stars
4.7k
Token cost
~600 tokens
SKILL.md length
262 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

  • Works in 3 steps: Synthesize Research Context → Select a Single Attack Pattern → Generate the Hunt Hypothesis
  • Narrowing a broad hunt topic into a single concrete attack pattern
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Writing a hunt hypothesis once research notes are complete

What it does

The skill runs after research is finished and before any hunt planning, environment scoping or query writing. It works in three ordered steps, each of which must complete before the next: synthesize the supplied research context, select one attack pattern, then write a structured hypothesis. New web searches and extra reference reading are not allowed, and the context is limited to the system internals findings, the adversary tradecraft findings and the candidate abuse patterns already identified.

When several patterns are possible, the agent picks the dominant one that is most realistic for the environment, clearly observable in the expected telemetry and actionable for hypothesis-driven investigation. The hypothesis follows the template in `references/hypothesis-template.md` and leaves out time windows, environment scope, data sources and constraints, which are set later when the hunt is assigned to a specific environment.

When your agent uses it

  • Narrowing a broad hunt topic into a single concrete attack pattern
  • Writing a hunt hypothesis once research notes are complete
  • Preparing a hypothesis before choosing data sources or analytics

Example prompts

  • “Using the research notes above on credential dumping, define the hunt focus and write the hypothesis.”
  • “Pick the most observable attack pattern from our tradecraft research and draft the hunt hypothesis.”
  • “Turn the candidate abuse patterns for scheduled tasks into one testable hypothesis.”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Synthesize Research Context
  2. Select a Single Attack Pattern
  3. Generate the Hunt Hypothesis

What it can do on your machine

Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Focus Definition loads about 600 tokens when it runs, and up to ~789 if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~600
With references · SKILL.md plus every file in references/, read only if the agent opens them
~789

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 262 words, ~600 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-focus-definition/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hunt-focus-definition
description
Define a focused hunt hypothesis by synthesizing completed system internals and adversary tradecraft research. Use this skill after research has been completed to narrow a high-level hunt topic into a single, concrete attack pattern with clear investigative intent. This skill produces a structured, testable hypothesis and should be used before selecting data sources, defining environment scope, or developing analytics.
metadata.short-description
Define a structured hunt hypothesis

Define Hunt Focus

This skill synthesizes completed research on system internals and adversary tradecraft into a single, focused hypothesis that defines what specific attack pattern will be investigated in the hunt.

It is executed after research has been completed and before detailed hunt planning, environment scoping, or query development.

Workflow

  • You MUST complete each step in order and MUST NOT proceed until the current step is complete.
  • You MUST NOT perform new web searches or introduce new research in this skill.
Step 1: Synthesize Research Context

Establish the context required to define a focused hunt hypothesis using the outputs of prior research.

  • Use the provided hunt research context.
  • Draw only from:
    • System internals research findings
    • Adversary tradecraft research findings
    • Identified candidate abuse patterns
  • Do NOT read additional reference documents or perform new research.

This step is complete when there is sufficient context to reason about a concrete, observable attack pattern.

Step 2: Select a Single Attack Pattern

Select one attack pattern to focus the hunt.

  • Choose the pattern that is:
    • Most realistic for the environment
    • Clearly observable based on expected telemetry
    • Actionable for hypothesis-driven investigation
  • If multiple patterns exist, select the dominant one.

Do NOT select multiple patterns.

Step 3: Generate the Hunt Hypothesis

Create a structured hunt hypothesis describing the selected attack pattern.

  • Use the format defined in references/hypothesis-template.md within this step ONLY.
  • Populate all required sections of the template.

Do NOT define time windows, environment scope, data sources, or constraints in this step.
Those details are defined later when the hunt is assigned to a specific environment or operational context.

© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .github/skills/hunt-focus-definition of OTRF/ThreatHunter-Playbook.

  • SKILL.md
  • references/hypothesis-template.md

Open the folder on GitHubat commit d310f38

Compare with similar skills

Hunt Focus Definition next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Focus Definition compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Focus Definition this skillOTRF/ThreatHunter-Playbook4.7k—~600Automated safety check: PassMIT
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Campaign Attribution Evidence Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0

Similar skills

  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    385 GitHub stars~12k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from OTRF/ThreatHunter-Playbook

  • Threat Hunt Blueprint Assembly

    OTRF/ThreatHunter-Playbook

    Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

    4.7k GitHub stars~1.2k tokensUpdated 8 mo ago
    Auto-check passed
  • Hunt Data Source Identification

    OTRF/ThreatHunter-Playbook

    Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

    4.7k GitHub stars~813 tokensUpdated 8 mo ago
    Auto-check passed
  • Threat Hunt Research Grounding

    OTRF/ThreatHunter-Playbook

    Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

    4.7k GitHub stars~1.3k tokensUpdated 8 mo ago
    Auto-check passed
  • Hunt Analytics Generation

    OTRF/ThreatHunter-Playbook

    Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

    4.7k GitHub stars~819 tokensUpdated 8 mo ago
    Auto-check passed

Categories

Questions about Hunt Focus Definition

What does Hunt Focus Definition do?

Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern. The skill runs after research is finished and before any hunt planning, environment scoping or query writing. It works in three ordered steps, each of which must complete before the next: synthesize the supplied research context, select one attack pattern, then write a structured hypothesis.

When should I use Hunt Focus Definition?

Hunt Focus Definition fits situations like: narrowing a broad hunt topic into a single concrete attack pattern; writing a hunt hypothesis once research notes are complete; preparing a hypothesis before choosing data sources or analytics.

How do I install Hunt Focus Definition in Claude Code?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-focus-definition -a claude-code`. Or copy the skill folder (.github/skills/hunt-focus-definition in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-focus-definition in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Focus Definition in Codex?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-focus-definition -a codex`. Or copy the skill folder (.github/skills/hunt-focus-definition in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-focus-definition in your project. Codex loads it when a task matches its description.

Can I use Hunt Focus Definition in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-focus-definition -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-focus-definition, .gemini/skills/hunt-focus-definition, .github/skills/hunt-focus-definition and .opencode/skills/hunt-focus-definition in your project.

What does Hunt Focus Definition need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Focus Definition is instructions for the agent only.

Does Hunt Focus Definition access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Focus Definition safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Focus Definition use?

Hunt Focus Definition is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Focus Definition use?

About 600 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 189 tokens, read only when the agent opens those files.

What are the alternatives to Hunt Focus Definition?

Skills that share tags, products or a category with Hunt Focus Definition: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Campaign Attribution Evidence Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Focus Definition?

OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.

Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.