threat-hunter

Conduct proactive threat hunting campaigns using MITRE ATT&CK frameworks.

6|1|Updated Feb 20, 2026
One-click install
npx skills add https://github.com/aviskaar/open-org --skill threat-hunter-aviskaar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunter
Source: https://github.com/aviskaar/open-org/tree/main/skills/threat-hunter
Command: npx skills add https://github.com/aviskaar/open-org --skill threat-hunter-aviskaar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates proactive threat hunting to detect and investigate advanced threats that may have bypassed existing security controls.

Core Features & Use Cases

  • Hypothesis-driven hunts: Leverages MITRE ATT&CK, threat intelligence, and behavioral anomalies.
  • IOC Sweeps: Regularly scans for known indicators of compromise across various log sources.
  • Adversary Emulation: Facilitates purple team exercises to test detection and response capabilities.
  • Use Case: Automatically initiate a hunt for new TTPs observed in recent threat intelligence reports to find potential compromises before they escalate.

Quick Start

Initiate a threat hunting sprint for new indicators of compromise.

Frequently Asked Questions about threat-hunter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct proactive threat hunting using MITRE ATT&CK frameworks?

Proactive threat hunting using MITRE ATT&CK frameworks involves driving hypothesis-based investigations to detect advanced threats bypassing existing security controls. This approach leverages behavioral anomaly investigation and threat intelligence to identify potential compromises before they escalate.

What is the best way to automate IOC sweeps across SIEM log sources?

Automating IOC sweeps across SIEM log sources requires integrating threat intelligence platforms to regularly scan for known indicators of compromise. This automated detection engineering identifies matching behavioral anomalies and threat artifacts across centralized security logs.

Do I need SIEM and threat intelligence platforms for hypothesis-driven threat hunting?

Yes, hypothesis-driven threat hunting requires integration with SIEM and threat intelligence platforms for comprehensive analysis. These integrations provide the centralized log sources and contextual threat data necessary to investigate behavioral anomalies and validate security hypotheses.

Can I use adversary emulation for purple team exercises to test detection capabilities?

Adversary emulation facilitates purple team exercises to actively test detection and response capabilities. By simulating new TTPs observed in recent threat intelligence reports, security teams can validate their defensive posture against advanced persistent threats.

How do I develop SIEM queries for behavioral anomaly investigation?

Developing SIEM queries for behavioral anomaly investigation involves applying threat intelligence and MITRE ATT&CK mappings to structured log data. This automated threat detection engineering translates hypotheses into targeted search queries to uncover hidden adversary activity.