hunt-apt

Integrate threat actor profiles and intelligence to locate and report on IoCs and MITRE techniques in real-time network traffic.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill hunt-apt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-apt
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/hunt-apt
Command: npx skills add https://github.com/dandye/ai-runbooks --skill hunt-apt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Hunts for APTs by consolidating threat intelligence from GTI, cross-referencing with SIEM results, and documenting findings to accelerate threat assessment.

Core Features & Use Cases

  • GTI-based threat actor profiling: Retrieve collection reports, MITRE tree, and timeline for the target actor.
  • IOC and TTP discovery: Identify IOCs and MITRE techniques related to the actor and search SIEM for matches.
  • Documentation & reporting: Compile findings into a structured hunt report with both positive and negative results.
  • Use Case: Use when you have threat actor name or GTI collection ID to initiate a targeted hunt.

Quick Start

Provide a threat actor name or GTI collection ID to start the hunt and produce a findings report.

Frequently Asked Questions about hunt-apt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I hunt APT threats using a threat actor name and SIEM data?

To hunt APT threats, you provide a threat actor name or GTI collection ID to retrieve intelligence reports, extract related IOCs and TTPs, and cross-reference these findings with SIEM search results. This process surfaces relevant matches within your environment.

What is the process for mapping MITRE techniques to SIEM search results?

Mapping MITRE techniques involves retrieving the MITRE tree for a target actor from GTI, identifying specific TTPs, and searching SIEM logs for matching indicators of compromise. It documents both positive and negative results in a structured dossier.

Can I use a GTI collection ID to generate a threat intelligence report?

Yes, you can use a GTI collection ID to initiate a targeted hunt that retrieves collection reports, actor timelines, and MITRE mappings. It consolidates these details into a structured hunt dossier documenting both positive and negative findings.

How do I extract IOCs from threat intelligence and check them against SIEM logs?

Extracting IOCs involves gathering threat actor intelligence from GTI and pulling associated indicators of compromise. The workflow then automatically searches your SIEM data for these specific IOCs to identify any existing matches within your environment.

What is the best way to document threat hunting findings for threat actors?

The best way to document threat hunting findings is compiling GTI reports, MITRE technique mappings, and SIEM search results into a structured hunt dossier. This report captures both positive and negative results to accelerate threat assessment.