secops-hunt

Guide analysts through SIEM searches, IOC gathering, and phased investigations.

513|130|Updated Apr 2, 2025
One-click install
npx skills add https://github.com/google/mcp-security --skill secops-hunt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secops-hunt
Source: https://github.com/google/mcp-security/tree/main/extensions/google-secops/skills/hunt
Command: npx skills add https://github.com/google/mcp-security --skill secops-hunt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides expert guidance for proactive threat hunting, helping security teams identify undetected threats, align workflows, and accelerate investigations.

Core Features & Use Cases

  • Structured hunting workflows: step-by-step guidance to plan, execute, and synthesize findings across SIEMs.
  • IOC-driven investigations: prompts and procedures for gathering IOCs, correlating with GTI data, and validating hypotheses.
  • Case and reporting support: guidance to create or update cases and generate concise hunter reports for stakeholders.

Quick Start

Start a proactive hunt by asking for IOCs related to a GTI Campaign or Threat Actor and walk through the Phase 1 IOC search, Phase 2 deep investigation, and result synthesis.

Frequently Asked Questions about secops-hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to start proactive threat hunting using IOCs?

Start proactive threat hunting by providing IOCs linked to a GTI Campaign or Threat Actor, then follow the guided Phase 1 IOC searches and Phase 2 deep investigations to synthesize findings and create cases.

How do I structure SIEM searches for threat investigations?

Structure SIEM searches for threat investigations by following a phased workflow that begins with IOC gathering and correlation in Phase 1, advancing to deep event lookups and hypothesis validation in Phase 2.

Can I use GTI campaign data to guide SOC case management?

Yes, you can use GTI campaign data to guide SOC case management by driving iterative lookups across events and IOCs, culminating in structured case creation or concise hunter reporting for stakeholders.

Does this threat hunting workflow support iterative IOC lookups?

The threat hunting workflow supports iterative IOC lookups across events and cases within a SOC environment, allowing analysts to progressively refine hypotheses during phased investigations.

How do I generate hunter reports after a deep investigation?

Generate hunter reports after a deep investigation by completing the phased IOC searches and event correlations, which structures the synthesized findings into concise reporting for stakeholders.