Hunt: Keyword and IOC Search

Search endpoints for keywords, IP addresses, and SHA256 hashes.

14|5|Updated May 14, 2020
One-click install
npx skills add https://github.com/op7ic/amphunt --skill hunt-keyword-and-ioc-search
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Hunt: Keyword and IOC Search
Source: https://github.com/op7ic/amphunt/tree/main/SKILLS/.claude/skills/hunt-keywords
Command: npx skills add https://github.com/op7ic/amphunt --skill hunt-keyword-and-ioc-search

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Search for multiple keywords, IP addresses, SHA256 hashes, or string patterns across all endpoints. This is the most flexible hunting tool - use it for custom IOC searches, threat intel integration, and ad-hoc investigations.

Core Features & Use Cases

  • Multi-keyword/IOC search across all endpoints
  • Supports IP addresses, SHA256 hashes, filenames, and strings
  • Use cases include threat-hunting, IOC enrichment, and ad-hoc investigations

Quick Start

Provide a config file and a keyword list to run the keyword/IOC search across all endpoints.

Frequently Asked Questions about Hunt: Keyword and IOC Search

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan endpoints for keywords and indicators of compromise across a network?

To scan endpoints for keywords and indicators of compromise, you need to provide a configuration file and a keyword list to drive a script-based search. This surfaces matching endpoints across the network and produces structured results for downstream tooling.

What types of indicators of compromise can I search for during threat hunting?

You can search for indicators of compromise including IP addresses, SHA256 hashes, filenames, and custom string patterns. This flexible keyword and IOC search supports multi-keyword queries across all endpoints for threat intel enrichment.

Do I need a configuration file and keyword list to run an IOC search?

Yes, running an IOC search requires a configuration file and a keywords list to drive the script-based search. These inputs define the search parameters and scope across all network endpoints.

What is the best way to use keyword searches for incident investigations?

The best way to use keyword searches for incident investigations is applying flexible, ad-hoc queries for custom string patterns and IOCs across all endpoints. This identifies and surfaces matching endpoints to support threat hunting workflows.

Can I use this for ad-hoc investigations and threat intel enrichment?

Yes, you can use this flexible hunting tool for ad-hoc investigations and threat intel enrichment. It applies custom keyword and IOC searches across all endpoints to produce structured results for downstream analysis.

What are the limitations of script-based endpoint searches for IOCs?

Script-based endpoint searches for IOCs require a predefined configuration file and keyword list to function. They are designed for structured result output and downstream tooling integration, which may limit purely spontaneous, unstructured threat hunting.