Agent skill

Hunting Threats

by trilwu in trilwu/secskills

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

MITAuto-check passedSecurity

Install Hunting Threats

skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills hunting-threats --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/hunting-threats .claude/skills/hunting-threats && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunting-threats
GitHub stars
157
Token cost
~3.5k tokens
SKILL.md length
1,378 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

  • Proactively searching for undetected compromise
  • SKILL.md covers When to Use, When NOT to Use, Hypothesis Before Query and Hunting Techniques, plus 9 more sections
  • Calls curl and python3; reaches defuddle.md
  • Validating an intel report against your environment

What it does

Hunting Threats is an agent skill from trilwu/secskills. Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic. Use when proactively searching for undetected compromise, validating an intel report against your environment, or converting a hunch into a repeatable hunt.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. It works with Microsoft Sentinel and Splunk. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Proactively searching for undetected compromise
  • Validating an intel report against your environment
  • Converting a hunch into a repeatable hunt

Example prompts

  • “/hunting-threats”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    Also links to:

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunting Threats loads about 3.5k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 1,378 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,378 words, ~3,475 tokens.

Download SKILL.mdSave it as .claude/skills/hunting-threats/SKILL.md (or your agent's skills folder).
name
hunting-threats
description
Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic. Use when proactively searching for undetected compromise, validating an intel report against your environment, or converting a hunch into a repeatable hunt.
verified
2026-07-27

Hunting Threats

Hunting starts from an assumption of failure: the controls are deployed, no alert has fired, and the adversary may still be present. The output is not usually a compromise — it is a detection, a telemetry gap, or a documented negative result. Hunts that only count as successful when they find something degrade into confirmation bias.

When to Use

  • Proactively searching for compromise that detection missed
  • Testing a specific hypothesis about attacker behaviour in your environment
  • Operationalizing a threat intel report against your telemetry
  • Validating that a control or detection actually works in production
  • Baselining an environment to enable future outlier analysis

When NOT to Use

  • Working an alert queue rather than a hypothesis — use triaging-security-alerts; a hunt starts from a question, triage from a queue
  • Confirmed incident in progress — use responding-to-incidents
  • Writing the rule for what you found — use engineering-detections
  • Sample analysis — use analyzing-malware
  • A packet capture to work through — use analyzing-network-traffic
  • A confirmed AWS compromise to investigate — use investigating-aws-incidents
  • Pivoting on indicators, tracking an actor, or producing a finished intel product — use producing-threat-intelligence; a hunt consumes intelligence, it does not produce it
  • Offensive testing of defenses — use the red team skills

Hypothesis Before Query

An unstructured search through logs is browsing, not hunting. Every hunt gets a written hypothesis in this shape:

Hypothesis: An adversary with [access level] is using [technique] to [objective], which would produce [observable] in [data source], which is distinguishable from normal because [discriminator].

If true, I expect to see: ... If false, I expect: ... Telemetry required: ... (verified present: yes/no)

If you cannot name the discriminator — what makes the malicious instance look different from the thousands of benign ones — the hunt is not ready. Go find the discriminator first; that research is the hunt.

Hypotheses come from: recent intel on actors targeting your sector, ATT&CK techniques with no detection coverage, crown-jewel assets and the paths to them, anomalies noticed during other work, and post-incident "what else would this actor have done."

Hunting Techniques

Stack counting (frequency analysis)

The workhorse. Aggregate a field, sort ascending, investigate the rare values. Malicious activity is usually rare; commodity noise is common.

sql
-- Splunk: rarest parent-child process pairs
index=sysmon EventCode=1
| stats count dc(host) as hosts by ParentImage, Image
| where count < 10 AND hosts < 3
| sort count
kusto
// KQL: rarely-seen signed binaries making external connections
DeviceNetworkEvents
| where RemoteIPType == "Public"
| summarize Count=count(), Hosts=dcount(DeviceName) by InitiatingProcessFolderPath
| where Hosts <= 2 and Count < 20
| order by Count asc

Stack the right field. Stacking Image finds unusual binaries; stacking ParentImage, Image finds unusual relationships, which is where living-off the-land abuse shows up (winword.exe → powershell.exe).

Outlier analysis

Same shape, different axis: what is normal for this entity?

  • A service account that has never used interactive logon, now doing so
  • A workstation talking to an internal subnet it has never touched
  • A user authenticating outside their historical hours and geography
  • A host whose process-count baseline shifted after a specific date
sql
-- Elastic ES|QL: first-seen external destinations per host
FROM logs-network-*
| WHERE destination.ip NOT IN CIDR("10.0.0.0/8","172.16.0.0/12","192.168.0.0/16")
| STATS first_seen = MIN(@timestamp), n = COUNT(*) BY host.name, destination.domain
| WHERE first_seen > NOW() - 7 days AND n > 20
Grouping and clustering

Cluster on a shared attribute to surface campaigns: same JA3/JA4 across unrelated hosts, same rare user agent, same certificate serial, same working hours, same directory of execution.

Intel-driven hunting

Take a report, extract the TTPs rather than the IOCs, and hunt those. The report's hashes and IPs are dead; its described behaviour is not.

Report says:  "uses schtasks to create a task running a DLL via rundll32"
Bad hunt:     search for the report's hash
Good hunt:    every scheduled task created in the last 90 days whose action
              references rundll32, stacked by task name and DLL path

High-Yield Hunting Grounds

Hypothesis areaWhat to look for
Execution via LOLBinsrundll32, regsvr32, mshta, certutil, bitsadmin, msiexec with network or unusual arguments; curl/wget piping to a shell on Linux
PersistenceScheduled tasks/cron/systemd units created recently; WMI event subscriptions (rare and almost always malicious); run keys; new services; authorized_keys modifications
Credential accessLSASS handle opens, ntds.dit copies, shadow-copy creation, Kerberos RC4 requests (4769 with encryption type 0x17), DCSync replication rights use
Lateral movementAdmin share writes followed by service creation, WinRM/WMI from non-admin hosts, SSH from workstations to servers, RDP chains
C2Beacon timing regularity, long-lived connections, DNS with high entropy or high subdomain cardinality, TLS with rare JA3/JA4
ExfiltrationOutbound volume outliers per host, archive creation followed by upload, cloud storage domains from servers, DNS TXT volume
Identity/cloudNew OAuth grants and consented apps, service principal credential additions, mail forwarding rules, role assignments outside change windows, StopLogging/trail deletion
Defense evasionEvent log clears (1102/104), Sysmon or EDR service stops, AMSI/ETW patch indicators, timestomping ($SI vs $FN mismatch)

The Hunt Loop

1. Hypothesis   (written, with a discriminator)
2. Scope        (data sources, time window, host population — decided up front)
3. Verify       (does the telemetry exist and cover the population?)
4. Query        (broad, then narrow — expect several iterations)
5. Investigate  (every candidate resolved to benign-explained or escalated)
6. Conclude     (found / not found / could-not-determine)
7. Convert      (detection rule, telemetry gap ticket, or documented baseline)
8. Document     (so the next person can re-run it, not re-derive it)

Every hunt produces an artifact, including hunts that find nothing. A negative result is a finding when it is documented with its scope and limitations: "no evidence of X across 4,200 endpoints over 90 days; note that 620 hosts lack the required telemetry." That sentence is worth more than an undocumented clean bill of health.

Scoping and Time Windows

  • Match the window to dwell-time reality, not convenience. If you look back 7 days for an actor with a 60-day median dwell time, a clean result is meaningless.
  • Confirm retention before you commit: a 90-day hunt over 30-day retention silently becomes a 30-day hunt.
  • Record which host populations are not covered by the telemetry you used. This is where the next intrusion will live.

When a Hunt Hits

Stop hunting and switch modes. Preserve first: pull the memory and triage package before anyone touches the host. Then hand to responding-to-incidents with the query, the raw results, and the timestamp of your first look — the response team needs to know what you touched and when, so your own activity does not contaminate the timeline.

Do not "just check one more thing" on a live suspect host. Interactive commands on a compromised box change evidence and can alert the operator.

Show full SKILL.md (514 more words)Show less

Rationalizations to Reject

  • "Nothing found, so we're clean." You searched one hypothesis over one data set for one window. Write down all three.
  • "Too much data to hunt." That is what stacking is for. Aggregate first; you are looking for the rare, not reading the common.
  • "The EDR would have alerted." The premise of hunting is that it did not.
  • "That's just noise." Characterize the noise. "Just noise" is where implants hide, and an uncharacterized benign cluster is an unexamined hypothesis.
  • "I'll remember what I searched." You will not, and neither will your successor. Undocumented hunts get repeated instead of extended.
  • "Let me just log into the suspicious host and look." You are now part of the timeline, and possibly a tripwire.
  • "We hunt when we have time." Ad-hoc hunting produces ad-hoc coverage. Schedule hunts against a prioritized technique backlog.

Deliverable

markdown
# Hunt: <name>          Date: <UTC>   Analyst: <name>
Hypothesis:             <as written above>
ATT&CK:                 T####.###
Scope:                  <data sources, host population, time window>
Telemetry verified:     <present / partial — name the gaps>
Queries:                <verbatim, so this is reproducible>
Results:                <candidates found, how each was resolved>
Conclusion:             found / not found / could-not-determine
Outputs:                <detection rule ID, telemetry gap ticket, baseline doc>
Limitations:            <what this hunt could not have seen>
<!-- attack:start -->

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Persistence (TA0003)

  • T1546.003 Windows Management Instrumentation Event Subscription — see also establishing-persistence

Defense Evasion (TA0005)

  • T1036 Masquerading — see also establishing-persistence
  • T1070.001 Clear Windows Event Logs — see also responding-to-incidents
  • T1218 System Binary Proxy Execution — see also escalating-windows-privileges
  • T1218.011 Rundll32 — see also analyzing-malware
  • T1562 Impair Defenses — see also responding-to-incidents
  • T1562.001 Disable or Modify Tools — see also responding-to-incidents

Collection (TA0009)

  • T1074 Data Staged — see also transferring-files
  • T1560 Archive Collected Data — see also transferring-files

Command and Control (TA0011)

  • T1071.004 DNS — see also engineering-detections, analyzing-network-traffic
  • T1219 Remote Access Software
  • T1568 Dynamic Resolution — see also analyzing-malware, analyzing-network-traffic
  • T1572 Protocol Tunneling — see also transferring-files

Exfiltration (TA0010)

  • T1030 Data Transfer Size Limits
  • T1048 Exfiltration Over Alternative Protocol — see also transferring-files, analyzing-network-traffic
  • T1567 Exfiltration Over Web Service — see also transferring-files

Impact (TA0040)

  • T1490 Inhibit System Recovery — see also responding-to-incidents
  • T1496 Resource Hijacking — see also exploiting-cloud-platforms

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

<!-- attack:end -->

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • engineering-detections — converting a successful hunt into a tested rule
  • responding-to-incidents — the handoff when a hunt confirms compromise
  • MITRE ATT&CK for hypothesis generation; PEAK and TaHiTI hunting frameworks
  • Sysmon, Zeek, osquery, Velociraptor, and cloud audit logs as core telemetry

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/hunting-threats of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Hunting Threats next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunting Threats compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunting Threats this skilltrilwu/secskills157—~3.5kAutomated safety check: PassMIT
Implementing Siem Use Cases For Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Siem Detectionbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Building Detection Rules With Sigmamukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Siem Loggingancoleman/ai-design-components525—~3.4kAutomated safety check: PassMIT

Similar skills

  • Implementing Siem Use Cases For Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Siem Detection

    briiirussell/cybersecurity-skills

    Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

    413 GitHub stars~2.6k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Detection Rules With Sigma

    mukul975/Anthropic-Cybersecurity-Skills

    Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Siem Logging

    ancoleman/ai-design-components

    Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

    525 GitHub stars~3.4k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Detection Sigma

    AgentSecOps/SecOpsAgentKit

    Generic detection rule creation and management using Sigma, the universal SIEM rule format.

    220 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunting Threats

What does Hunting Threats do?

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…. Hunting Threats is an agent skill from trilwu/secskills. Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic.

When should I use Hunting Threats?

Hunting Threats fits situations like: proactively searching for undetected compromise; validating an intel report against your environment; converting a hunch into a repeatable hunt.

How do I install Hunting Threats in Claude Code?

Run `npx skills add trilwu/secskills --skill hunting-threats -a claude-code`. Or copy the skill folder (secskills-defense/skills/hunting-threats in trilwu/secskills) into .claude/skills/hunting-threats in your project. Claude Code loads it when a task matches its description.

How do I install Hunting Threats in Codex?

Run `npx skills add trilwu/secskills --skill hunting-threats -a codex`. Or copy the skill folder (secskills-defense/skills/hunting-threats in trilwu/secskills) into .agents/skills/hunting-threats in your project. Codex loads it when a task matches its description.

Can I use Hunting Threats in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill hunting-threats -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunting-threats, .gemini/skills/hunting-threats, .github/skills/hunting-threats and .opencode/skills/hunting-threats in your project.

What does Hunting Threats need to run?

Going by SKILL.md and its folder, Hunting Threats needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.

Does Hunting Threats access the network?

SKILL.md names 2 domains. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.

Is Hunting Threats safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunting Threats use?

Hunting Threats is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunting Threats use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunting Threats?

Skills that share tags, products or a category with Hunting Threats: Implementing Siem Use Cases For Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Siem Detection (briiirussell/cybersecurity-skills, 413 stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Detection Rules With Sigma (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunting Threats?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.