hunt

Analyze PCAP files and Suricata EVE JSON logs to detect malicious network activity.

2|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-stamusnetworks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt
Source: https://github.com/StamusNetworks/stamus-ai-tools/tree/main/plugins/suricata-analyze/skills/hunt
Command: npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-stamusnetworks

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Analyzes PCAPs and Suricata EVE JSON logs to surface hidden threats and anomalous network activity by applying threat-hunting techniques.

Core Features & Use Cases

  • Unified analysis of PCAPs and EVE JSON logs to detect suspicious patterns and security events.
  • 10+ structured hunting queries for detecting C2 activity, data exfiltration, DNS tunneling, TLS anomalies, and beaconing.
  • Container-friendly workflow with optional rules-based context integration for testing and validation.
  • Incident-ready outputs and workflow integration for investigations.

Quick Start

Analyze a provided PCAP or EVE JSON log to surface critical alerts and suspicious patterns.

Frequently Asked Questions about hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect malware C2 activity and DNS tunneling from PCAP files?

Detecting malware C2 activity and DNS tunneling from PCAP files is achieved by applying structured threat-hunting queries to surface suspicious network patterns and security events. The analysis identifies malicious traffic using Suricata EVE JSON logs and packet captures to produce investigator-ready results.

What is the best way to hunt for TLS anomalies and beaconing in Suricata EVE logs?

Hunting for TLS anomalies and beaconing in Suricata EVE logs is best done using jq-based queries that analyze EVE JSON output for suspicious patterns. This surfaces hidden threats and anomalous network activity by applying threat-hunting techniques to captured traffic.

Can I analyze PCAPs for data exfiltration without configuring local Suricata rules?

You can analyze PCAPs for data exfiltration without local Suricata rules, as the workflow supports security monitoring with or without them. Optional rules-based context integration is available for testing and validation during threat-hunting workflows.

Does the threat hunting workflow support container-friendly execution for incident investigations?

The threat hunting workflow supports container-friendly execution for incident investigations, analyzing PCAPs and Suricata EVE JSON logs to surface hidden threats. It delivers incident-ready outputs and workflow integration for security monitoring.