Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .claude/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .agents/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .cursor/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .gemini/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .github/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill hunting-threats -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "hunting-threats" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats into .opencode/skills/hunting-threats/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunting-threats", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
hunting-threats
GitHub stars
157
Token cost
~3.5k tokens
SKILL.md length
1,378 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT
At a glance
Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…
Proactively searching for undetected compromise
SKILL.md covers When to Use, When NOT to Use, Hypothesis Before Query and Hunting Techniques, plus 9 more sections
Calls curl and python3; reaches defuddle.md
Validating an intel report against your environment
What it does
Hunting Threats is an agent skill from trilwu/secskills. Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic. Use when proactively searching for undetected compromise, validating an intel report against your environment, or converting a hunch into a repeatable hunt.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security operations. It works with Microsoft Sentinel and Splunk. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
When your agent uses it
Proactively searching for undetected compromise
Validating an intel report against your environment
Converting a hunch into a repeatable hunt
Example prompts
“/hunting-threats”
Requirements
Python 3
What it can do on your machine
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
curl
python3
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
defuddle.md
Also links to:
attack.mitre.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Hunting Threats loads about 3.5k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 1,378 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~97
When it runs· the whole SKILL.md, loaded when a task matches
~3.5k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/hunting-threats/SKILL.md (or your agent's skills folder).
name
hunting-threats
description
Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic. Use when proactively searching for undetected compromise, validating an intel report against your environment, or converting a hunch into a repeatable hunt.
verified
2026-07-27
Hunting Threats
Hunting starts from an assumption of failure: the controls are deployed, no
alert has fired, and the adversary may still be present. The output is not
usually a compromise — it is a detection, a telemetry gap, or a documented
negative result. Hunts that only count as successful when they find something
degrade into confirmation bias.
When to Use
Proactively searching for compromise that detection missed
Testing a specific hypothesis about attacker behaviour in your environment
Operationalizing a threat intel report against your telemetry
Validating that a control or detection actually works in production
Baselining an environment to enable future outlier analysis
When NOT to Use
Working an alert queue rather than a hypothesis — use
triaging-security-alerts; a hunt starts from a question, triage from a queue
Confirmed incident in progress — use responding-to-incidents
Writing the rule for what you found — use engineering-detections
Sample analysis — use analyzing-malware
A packet capture to work through — use analyzing-network-traffic
A confirmed AWS compromise to investigate — use investigating-aws-incidents
Pivoting on indicators, tracking an actor, or producing a finished intel
product — use producing-threat-intelligence; a hunt consumes intelligence,
it does not produce it
Offensive testing of defenses — use the red team skills
Hypothesis Before Query
An unstructured search through logs is browsing, not hunting. Every hunt gets
a written hypothesis in this shape:
Hypothesis: An adversary with [access level] is using [technique] to
[objective], which would produce [observable] in [data source], which is
distinguishable from normal because [discriminator].
If true, I expect to see: ...
If false, I expect: ...
Telemetry required: ... (verified present: yes/no)
If you cannot name the discriminator — what makes the malicious instance look
different from the thousands of benign ones — the hunt is not ready. Go find
the discriminator first; that research is the hunt.
Hypotheses come from: recent intel on actors targeting your sector, ATT&CK
techniques with no detection coverage, crown-jewel assets and the paths to
them, anomalies noticed during other work, and post-incident "what else would
this actor have done."
Hunting Techniques
Stack counting (frequency analysis)
The workhorse. Aggregate a field, sort ascending, investigate the rare values.
Malicious activity is usually rare; commodity noise is common.
sql
-- Splunk: rarest parent-child process pairs
index=sysmon EventCode=1
| stats count dc(host) as hosts by ParentImage, Image
| where count < 10 AND hosts < 3
| sort count
kusto
// KQL: rarely-seen signed binaries making external connections
DeviceNetworkEvents
| where RemoteIPType == "Public"
| summarize Count=count(), Hosts=dcount(DeviceName) by InitiatingProcessFolderPath
| where Hosts <= 2 and Count < 20
| order by Count asc
Stack the right field. Stacking Image finds unusual binaries; stacking
ParentImage, Image finds unusual relationships, which is where living-off
the-land abuse shows up (winword.exe → powershell.exe).
Outlier analysis
Same shape, different axis: what is normal for this entity?
A service account that has never used interactive logon, now doing so
A workstation talking to an internal subnet it has never touched
A user authenticating outside their historical hours and geography
A host whose process-count baseline shifted after a specific date
sql
-- Elastic ES|QL: first-seen external destinations per host
FROM logs-network-*
| WHERE destination.ip NOT IN CIDR("10.0.0.0/8","172.16.0.0/12","192.168.0.0/16")
| STATS first_seen = MIN(@timestamp), n = COUNT(*) BY host.name, destination.domain
| WHERE first_seen > NOW() - 7 days AND n > 20
Grouping and clustering
Cluster on a shared attribute to surface campaigns: same JA3/JA4 across
unrelated hosts, same rare user agent, same certificate serial, same working
hours, same directory of execution.
Intel-driven hunting
Take a report, extract the TTPs rather than the IOCs, and hunt those. The
report's hashes and IPs are dead; its described behaviour is not.
Report says: "uses schtasks to create a task running a DLL via rundll32"
Bad hunt: search for the report's hash
Good hunt: every scheduled task created in the last 90 days whose action
references rundll32, stacked by task name and DLL path
High-Yield Hunting Grounds
Hypothesis area
What to look for
Execution via LOLBins
rundll32, regsvr32, mshta, certutil, bitsadmin, msiexec with network or unusual arguments; curl/wget piping to a shell on Linux
Persistence
Scheduled tasks/cron/systemd units created recently; WMI event subscriptions (rare and almost always malicious); run keys; new services; authorized_keys modifications
Credential access
LSASS handle opens, ntds.dit copies, shadow-copy creation, Kerberos RC4 requests (4769 with encryption type 0x17), DCSync replication rights use
Lateral movement
Admin share writes followed by service creation, WinRM/WMI from non-admin hosts, SSH from workstations to servers, RDP chains
C2
Beacon timing regularity, long-lived connections, DNS with high entropy or high subdomain cardinality, TLS with rare JA3/JA4
Exfiltration
Outbound volume outliers per host, archive creation followed by upload, cloud storage domains from servers, DNS TXT volume
Identity/cloud
New OAuth grants and consented apps, service principal credential additions, mail forwarding rules, role assignments outside change windows, StopLogging/trail deletion
Defense evasion
Event log clears (1102/104), Sysmon or EDR service stops, AMSI/ETW patch indicators, timestomping ($SI vs $FN mismatch)
The Hunt Loop
1. Hypothesis (written, with a discriminator)
2. Scope (data sources, time window, host population — decided up front)
3. Verify (does the telemetry exist and cover the population?)
4. Query (broad, then narrow — expect several iterations)
5. Investigate (every candidate resolved to benign-explained or escalated)
6. Conclude (found / not found / could-not-determine)
7. Convert (detection rule, telemetry gap ticket, or documented baseline)
8. Document (so the next person can re-run it, not re-derive it)
Every hunt produces an artifact, including hunts that find nothing. A
negative result is a finding when it is documented with its scope and
limitations: "no evidence of X across 4,200 endpoints over 90 days; note that
620 hosts lack the required telemetry." That sentence is worth more than an
undocumented clean bill of health.
Scoping and Time Windows
Match the window to dwell-time reality, not convenience. If you look back
7 days for an actor with a 60-day median dwell time, a clean result is
meaningless.
Confirm retention before you commit: a 90-day hunt over 30-day retention
silently becomes a 30-day hunt.
Record which host populations are not covered by the telemetry you used.
This is where the next intrusion will live.
When a Hunt Hits
Stop hunting and switch modes. Preserve first: pull the memory and triage
package before anyone touches the host. Then hand to
responding-to-incidents with the query, the raw results, and the timestamp
of your first look — the response team needs to know what you touched and
when, so your own activity does not contaminate the timeline.
Do not "just check one more thing" on a live suspect host. Interactive
commands on a compromised box change evidence and can alert the operator.
Show full SKILL.md (514 more words)Show less
Rationalizations to Reject
"Nothing found, so we're clean." You searched one hypothesis over one data
set for one window. Write down all three.
"Too much data to hunt." That is what stacking is for. Aggregate first;
you are looking for the rare, not reading the common.
"The EDR would have alerted." The premise of hunting is that it did not.
"That's just noise." Characterize the noise. "Just noise" is where implants
hide, and an uncharacterized benign cluster is an unexamined hypothesis.
"I'll remember what I searched." You will not, and neither will your
successor. Undocumented hunts get repeated instead of extended.
"Let me just log into the suspicious host and look." You are now part of
the timeline, and possibly a tripwire.
"We hunt when we have time." Ad-hoc hunting produces ad-hoc coverage.
Schedule hunts against a prioritized technique backlog.
Deliverable
markdown
# Hunt: <name> Date: <UTC> Analyst: <name>
Hypothesis: <as written above>
ATT&CK: T####.###
Scope: <data sources, host population, time window>
Telemetry verified: <present / partial — name the gaps>
Queries: <verbatim, so this is reproducible>
Results: <candidates found, how each was resolved>
Conclusion: found / not found / could-not-determine
Outputs: <detection rule ID, telemetry gap ticket, baseline doc>
Limitations: <what this hunt could not have seen>
<!-- attack:start -->
ATT&CK Coverage
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Persistence (TA0003)
T1546.003 Windows Management Instrumentation Event Subscription — see also establishing-persistence
Defense Evasion (TA0005)
T1036 Masquerading — see also establishing-persistence
T1070.001 Clear Windows Event Logs — see also responding-to-incidents
T1218 System Binary Proxy Execution — see also escalating-windows-privileges
T1048 Exfiltration Over Alternative Protocol — see also transferring-files, analyzing-network-traffic
T1567 Exfiltration Over Web Service — see also transferring-files
Impact (TA0040)
T1490 Inhibit System Recovery — see also responding-to-incidents
T1496 Resource Hijacking — see also exploiting-cloud-platforms
Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
Reading External Sources
Fetch public advisories, specifications, and vendor reports as Markdown:
bash
curl -sL "https://defuddle.md/<url>" # scheme in the path is optional
This strips page boilerplate — roughly 78% fewer tokens on a prose page — and
returns the full text rather than a summary, so you can grep it and trust a
negative result.
Three things it is not for. Fetch JSON and API responses raw, because
readability extraction mangles structured data. Fetch authenticated or
JavaScript-rendered pages directly, because it retrieves them anonymously. And
never route adversary infrastructure (phishing links, C2, malware hosting),
client-owned hosts, or engagement URLs through it — the request leaves
your machine to a third party, and for live adversary infrastructure it also
tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
References
engineering-detections — converting a successful hunt into a tested rule
responding-to-incidents — the handoff when a hunt confirms compromise
MITRE ATT&CK for hypothesis generation; PEAK and TaHiTI hunting frameworks
Sysmon, Zeek, osquery, Velociraptor, and cloud audit logs as core telemetry
Hunting Threats next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.
Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…
Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…. Hunting Threats is an agent skill from trilwu/secskills. Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic.
When should I use Hunting Threats?
Hunting Threats fits situations like: proactively searching for undetected compromise; validating an intel report against your environment; converting a hunch into a repeatable hunt.
How do I install Hunting Threats in Claude Code?
Run `npx skills add trilwu/secskills --skill hunting-threats -a claude-code`. Or copy the skill folder (secskills-defense/skills/hunting-threats in trilwu/secskills) into .claude/skills/hunting-threats in your project. Claude Code loads it when a task matches its description.
How do I install Hunting Threats in Codex?
Run `npx skills add trilwu/secskills --skill hunting-threats -a codex`. Or copy the skill folder (secskills-defense/skills/hunting-threats in trilwu/secskills) into .agents/skills/hunting-threats in your project. Codex loads it when a task matches its description.
Can I use Hunting Threats in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill hunting-threats -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunting-threats, .gemini/skills/hunting-threats, .github/skills/hunting-threats and .opencode/skills/hunting-threats in your project.
What does Hunting Threats need to run?
Going by SKILL.md and its folder, Hunting Threats needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.
Does Hunting Threats access the network?
SKILL.md names 2 domains. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Is Hunting Threats safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Hunting Threats use?
Hunting Threats is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Hunting Threats use?
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Hunting Threats?
Skills that share tags, products or a category with Hunting Threats: Implementing Siem Use Cases For Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Siem Detection (briiirussell/cybersecurity-skills, 413 stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Building Detection Rules With Sigma (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Hunting Threats?
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.