hunt-generic

Identify high-priority threats in PCAP and Suricata EVE JSON network traffic.

2|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-generic
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-generic
Source: https://github.com/StamusNetworks/stamus-ai-tools/tree/main/plugins/suricata-analyze/skills/hunt-generic
Command: npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-generic

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Analyzes network traffic data (PCAP and Suricata EVE JSON) to identify high-priority threats and suspicious activity, enabling faster detection and response.

Core Features & Use Cases

  • Structured threat hunting across PCAP and EVE logs, including C2 detection, data exfiltration, DNS tunneling, TLS anomalies, and beaconing.
  • Step-by-step hunts that produce actionable indicators (flow IDs, src/dst IPs, ports) for incident responders.
  • Use cases include SOC threat hunting, incident containment, and validation of IDS rule effectiveness.

Quick Start

Run the provided hunting queries against your PCAP or EVE JSON dataset and review the consolidated findings to begin investigation.

Frequently Asked Questions about hunt-generic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I hunt for threats in PCAP and Suricata EVE JSON logs?

Threat hunting in PCAP and Suricata EVE JSON involves running structured hunts to identify high-priority threats and suspicious activity. It analyzes network traffic to detect C2 activity, data exfiltration, DNS tunneling, TLS anomalies, and beaconing, producing actionable indicators for incident response.

What specific network anomalies can I detect in Suricata EVE JSON logs?

You can detect C2 activity, data exfiltration, DNS tunneling, TLS anomalies, and beaconing in Suricata EVE JSON logs. The structured hunts produce flow IDs, source/destination IPs, ports, and summaries of alerts or anomalies for incident responders.

Can I use this for incident response and validating IDS rule effectiveness?

Yes, this supports SOC threat hunting, incident containment, and validation of IDS rule effectiveness. It analyzes PCAP-derived datasets and Suricata EVE JSON logs to produce actionable indicators including flow IDs, source and destination IPs, and ports for investigation.

What is the best way to investigate suspicious network traffic captured in PCAPs?

The best way to investigate suspicious network traffic captured in PCAPs is running structured hunting queries against your dataset. This process identifies high-priority threats and produces consolidated findings with flow IDs, IPs, and ports to begin investigation.

Does this skill work with PCAP-derived JSON datasets or only raw PCAP files?

This skill is applicable to both PCAP-derived JSON datasets and Suricata EVE JSON logs. It analyzes these formats to identify high-priority threats and suspicious activity, producing flow IDs, source and destination IPs, ports, and summaries of alerts or anomalies.