Agent skill

Threat Hunt Research Grounding

by OTRF in OTRF/ThreatHunter-Playbook

Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

MITAuto-check passedSecurity

Install Threat Hunt Research Grounding

skills CLI
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .claude/skills/hunt-research-system-and-tradecraft && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-research-system-and-tradecraft
GitHub stars
4.7k
Token cost
~1.3k tokens
SKILL.md length
584 words
Files
8 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

  • Works in 5 steps: Normalize the input → Research system internals → Research adversary tradecraft → …
  • Starting a threat hunt on a topic you don't yet understand deeply
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Grounding a hunt hypothesis in real system behavior before writing it

What it does

This skill works through a fixed step order and refuses to read reference documents or run web searches outside the step that calls for them. It first normalizes a vague topic like WMI abuse into an explicit scope, naming the concrete platform or feature in scope and stating any assumption needed to remove ambiguity, asking the user only when critical details are genuinely missing.

It then researches system internals with a capped number of web searches per step, stopping once core capabilities and observability are understood, and separately researches adversary tradecraft the same way, producing citable sources, candidate abuse patterns, and key assumptions rather than raw notes or a finished hunt hypothesis. This output is meant to inform the hunt-hypothesis and data-source steps that follow it, not replace them.

When your agent uses it

  • Starting a threat hunt on a topic you don't yet understand deeply
  • Grounding a hunt hypothesis in real system behavior before writing it
  • Researching how a specific Windows feature is realistically abused

Example prompts

  • “Research WMI internals and known abuse patterns before we plan a hunt.”
  • “Ground a Kerberos abuse hunt in real adversary tradecraft.”
  • “What assumptions should we state before hunting for this abuse pattern?”

Requirements

  • Tavily search access

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Normalize the input
  2. Research system internals
  3. Research adversary tradecraft
  4. Identify candidate abuse patterns
  5. Write the research summary

What it can do on your machine

Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Hunt Research Grounding loads about 1.3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 584 words, ~1,253 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-research-system-and-tradecraft/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
hunt-research-system-and-tradecraft
description
Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.
metadata.short-description
Research system internals and adversary tradecraft for hunt planning

Research System Internals and Adversary Tradecraft

Provide structured research context at the start of a threat hunt by incrementally applying only the references explicitly called for in each workflow step. This skill establishes a grounded understanding of system capabilities and adversary behaviors so downstream hunt planning reflects how the environment actually works and how it is realistically abused.

Workflow

  • You MUST complete each step in order and MUST NOT proceed until the current step is complete.
  • You MUST NOT read reference documents or perform web searches unless the current step explicitly instructs you to do so.
  • Do NOT output raw notes, coverage checks, intermediate reasoning, or step summaries.
  • Do NOT restate findings from previous steps outside the final report structure.
Step 1: Normalize the input

Translate the user's high-level topic into a precise research scope before any investigation begins. This step exists to remove ambiguity and establish a shared frame for system and adversary analysis.

This step is complete only when the scope is explicit and unambiguous.

  • Record the topic exactly as provided (e.g., "WMI abuse", "Kerberos abuse").
  • Identify the concrete platform, system, or feature in scope.
  • Resolve ambiguity by stating explicit assumptions when needed.
  • Set the research intent to cover both normal system behavior and adversary abuse unless the user explicitly restricts it.
  • If critical scope details are missing or ambiguous, request clarification from the user.
  • If sufficient information is available, proceed without further confirmation.

Do NOT perform web searches or read reference documents during this step.

Step 2: Research system internals

Build a grounded understanding of how the system functions under normal conditions.

  • Start with searching the web using Tavily:tavily-search, and do not exceed 5 total web search queries in this step.
  • Stop searching once core system concepts, capabilities, and observability are sufficiently understood.
  • Apply guidance from references/tavily-search-guide.md.
  • Collect raw research notes focused on system behavior and capabilities.

During this step only:

  • Evaluate coverage using references/system-internals-research-guide.md within this step ONLY.
  • If gaps are identified, perform targeted follow-up research (web or internal knowledge) and update the notes.

Do NOT read adversary tradecraft reference documents in this step. Do not synthesize or summarize findings.

Show full SKILL.md (230 more words)Show less
Step 3: Research adversary tradecraft

Analyze how adversaries leverage or manipulate the system capabilities identified above.

  • Start with searching the web using Tavily:tavily-search, and do not exceed 5 total web search queries in this step.
  • Stop searching once dominant abuse behaviors and execution patterns are clearly understood.
  • Apply guidance from references/tavily-search-guide.md.
  • Collect raw research notes focused on behavior and outcomes, not tools.

During this step only:

  • Evaluate coverage using references/adversary-tradecraft-research-guide.md within this step ONLY.
  • If gaps are identified, perform targeted follow-up research (web or internal knowledge) and update the notes.

Do Not read system internals reference documents in this step. Do Not synthesize or summarize findings.

Step 4: Identify candidate abuse patterns

Using the completed adversary tradecraft research, extract concrete abuse patterns that will guide hypothesis-driven hunting.

  • Identify the top 3–5 distinct patterns (or fewer if one clearly dominates).
  • For each pattern, record:
    • Adversary behavior
    • System capability or assumption being abused
    • High-level observables or effects
    • Common variations that preserve the same outcome

Porivide the list of patterns if they exist. They must be tool-agnostic and suitable for use in the next hunt-planning step.

Step 5: Write the research summary

Produce the final structured research artifact using the following documents within this step ONLY.

  • Structure the output using references/research-summary-template.md.
  • Format and cite sources using references/research-citations-guide.md.

This step is synthesis only. Do not introduce new research, assumptions, or evidence at this stage.

© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in .github/skills/hunt-research-system-and-tradecraft of OTRF/ThreatHunter-Playbook.

  • SKILL.md
  • examples/wmi_abuse.md
  • examples/wmi_abuse_v2.md
  • references/adversary-tradecraft-research-guide.md
  • references/research-citations-guide.md
  • references/research-summary-template.md
  • references/system-internals-research-guide.md
  • references/tavily-search-guide.md

Open the folder on GitHubat commit d310f38

Compare with similar skills

Threat Hunt Research Grounding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Hunt Research Grounding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Hunt Research Grounding this skillOTRF/ThreatHunter-Playbook4.7k—~1.3kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
X Raypashov/skills1.2k1 repos~10kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Osintsmixs/osint-skill141—~5.5kAutomated safety check: PassMIT

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    141 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Run Assert Eval

    responsibleai/ASSERT

    Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

    330 GitHub stars~11k tokensUpdated 2 days ago
    SecurityAuto-check: notes

More from OTRF/ThreatHunter-Playbook

  • Threat Hunt Blueprint Assembly

    OTRF/ThreatHunter-Playbook

    Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.

    4.7k GitHub stars~1.2k tokensUpdated 9 mo ago
    Auto-check passed
  • Hunt Data Source Identification

    OTRF/ThreatHunter-Playbook

    Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.

    4.7k GitHub stars~813 tokensUpdated 9 mo ago
    Auto-check passed
  • Hunt Focus Definition

    OTRF/ThreatHunter-Playbook

    Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.

    4.7k GitHub stars~600 tokensUpdated 9 mo ago
    Auto-check passed
  • Hunt Analytics Generation

    OTRF/ThreatHunter-Playbook

    Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

    4.7k GitHub stars~819 tokensUpdated 9 mo ago
    Auto-check passed

Works with

Categories

Questions about Threat Hunt Research Grounding

What does Threat Hunt Research Grounding do?

Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. This skill works through a fixed step order and refuses to read reference documents or run web searches outside the step that calls for them. It first normalizes a vague topic like WMI abuse into an explicit scope, naming the concrete platform or feature in scope and stating any assumption needed to remove ambiguity, asking the user only when critical details are genuinely missing.

When should I use Threat Hunt Research Grounding?

Threat Hunt Research Grounding fits situations like: starting a threat hunt on a topic you don't yet understand deeply; grounding a hunt hypothesis in real system behavior before writing it; researching how a specific Windows feature is realistically abused.

How do I install Threat Hunt Research Grounding in Claude Code?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a claude-code`. Or copy the skill folder (.github/skills/hunt-research-system-and-tradecraft in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-research-system-and-tradecraft in your project. Claude Code loads it when a task matches its description.

How do I install Threat Hunt Research Grounding in Codex?

Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a codex`. Or copy the skill folder (.github/skills/hunt-research-system-and-tradecraft in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-research-system-and-tradecraft in your project. Codex loads it when a task matches its description.

Can I use Threat Hunt Research Grounding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-research-system-and-tradecraft, .gemini/skills/hunt-research-system-and-tradecraft, .github/skills/hunt-research-system-and-tradecraft and .opencode/skills/hunt-research-system-and-tradecraft in your project.

What does Threat Hunt Research Grounding need to run?

SKILL.md names no scripts, command-line tools or credentials: Threat Hunt Research Grounding is instructions for the agent only. Our summary lists: Tavily search access.

Does Threat Hunt Research Grounding access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Hunt Research Grounding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Threat Hunt Research Grounding use?

Threat Hunt Research Grounding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Hunt Research Grounding use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Threat Hunt Research Grounding?

Skills that share tags, products or a category with Threat Hunt Research Grounding: Security And Hardening (penpot/penpot, 61k stars), X Ray (pashov/skills, 1.2k stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Hunt Research Grounding?

OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.

Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.