hunt-threat

Conduct hypothesis-driven threat hunts across SIEM and telemetry sources with GTI enrichment.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill hunt-threat
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-threat
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/hunt-threat
Command: npx skills add https://github.com/dandye/ai-runbooks --skill hunt-threat

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Proactive threat hunting based on threat intelligence, TTPs, or anomalies is complex and time-consuming; this skill provides a structured approach for Tier 3 analysts and threat hunters to generate hypotheses and conduct iterative investigations.

Core Features & Use Cases

  • Hypothesis-driven hunting using GTI reports and observed anomalies to guide targeted searches.
  • Iterative search and pivoting across SIEM, telemetry, and enrichment data to uncover leads.
  • Comprehensive documentation and hunt-case tracking from hypothesis to resolution, including GTI enrichment results.
  • Use Case: When a new IOC or actor TTP is observed, launch a focused hunt to validate presence across targets and pivot on findings.

Quick Start

Provide a HUNT_HYPOTHESIS and scope, then initiate initial GTI-enriched queries and begin recording findings.

Frequently Asked Questions about hunt-threat

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is hypothesis-driven threat hunting and how does it use threat intelligence?

Hypothesis-driven threat hunting uses threat intelligence, TTPs, or anomalies to guide targeted searches. Analysts formulate hypotheses from GTI reports, execute iterative SIEM queries, pivot on findings, and document results to produce actionable findings.

How do I conduct iterative threat hunts and pivot across SIEM queries?

Conduct iterative threat hunts by formulating advanced SIEM queries, applying GTI enrichment, and pivoting across telemetry data. This structured approach establishes a hunt case ID, tracks findings from hypothesis to resolution, and continuously documents results.

Can I use TTPs and anomalies to initiate proactive threat hunting?

Yes, you can initiate proactive threat hunting using observed actor TTPs or anomalies. When a new IOC or TTP is observed, launch a focused hunt to validate presence across targets, apply GTI enrichment, and pivot on findings.

What is the best way to document threat hunting results and track hunt cases?

The best way to document threat hunting results is through comprehensive hunt-case tracking from hypothesis to resolution. Establish a hunt case ID, record iterative queries, document pivots, and include GTI enrichment results for actionable findings.

Does threat hunting with GTI enrichment work for Tier 3 advanced analysts?

Yes, threat hunting with GTI enrichment is designed for Tier 3 analysts and threat hunters. It provides a structured approach to generate hypotheses and conduct iterative investigations using advanced queries across SIEM and telemetry sources.

How do I start a threat hunt when a new IOC is observed?

To start a threat hunt when a new IOC is observed, provide a hunt hypothesis and scope, then initiate initial GTI-enriched queries. Establish a hunt case ID and begin recording findings and pivots across telemetry sources.