Threat Hunt

Automate security event investigation and threat hunting workflows.

285|33|Updated Jan 31, 2026
One-click install
npx skills add https://github.com/backbay-labs/clawdstrike --skill threat-hunt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Threat Hunt
Source: https://github.com/backbay-labs/clawdstrike/tree/main/clawdstrike-plugin/skills/threat-hunt
Command: npx skills add https://github.com/backbay-labs/clawdstrike --skill threat-hunt

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill simplifies the process of investigating security events and suspicious activity, reducing the time and effort required for incident response and threat hunting.

Core Features & Use Cases

  • Investigation Workflow: Automates the investigation of security events with a structured approach.
  • Timeline Analysis: Provides a chronological view of recent events for a comprehensive understanding.
  • Query and Filter: Enables drilling into specific criteria to find blocked actions and identify patterns.
  • Correlate Events: Detects patterns across events to identify attack sequences and lateral movement.
  • Check IOCs: Submits suspicious indicators against threat intelligence for thorough analysis.
  • Generate Report: Produces a structured investigation summary with event timelines and findings.
  • MITRE ATT&CK Support: Offers quick reference to common techniques and mapping to MCP tools.
  • Incident Classification: Classifies incidents into severity levels for prioritized response.
  • Response Guidelines: Provides guidelines for presenting findings and recommending remediation steps.

Quick Start

Use the threat hunt skill to initiate an investigation on suspicious activity.

Frequently Asked Questions about Threat Hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate threat hunting and security event investigation?

Automate threat hunting by applying a structured investigation workflow to security logs, which correlates events to identify attack sequences and lateral movement. This process reduces the manual effort required for incident response.

How does correlating security events help identify lateral movement?

Correlating security events detects patterns across multiple log sources to reveal attack sequences and lateral movement within a network. This chronological timeline analysis provides a comprehensive understanding of malicious activity.

Can I map suspicious activity to MITRE ATT&CK techniques during an incident response?

You can map suspicious activity to MITRE ATT&CK techniques during incident response using quick reference guides. This helps classify incident severity and provides guidelines for recommending targeted remediation steps.

Does threat hunting work with existing security logs and event streams?

Threat hunting requires access to existing security logs and event streams for analysis. It filters specific criteria to find blocked actions and submits suspicious indicators against threat intelligence for thorough analysis.

What is the best way to generate a structured investigation report for a breach?

The best way to generate a structured investigation report for a breach is to automate the compilation of event timelines and findings. This produces a summary that classifies incident severity and outlines response guidelines.

How do I check IOCs against threat intelligence during a security investigation?

Check IOCs during a security investigation by submitting suspicious indicators against threat intelligence sources. This analysis validates indicators of compromise and helps prioritize response actions based on incident severity.

Related Skills