threat-hunter

Validate adversary hypotheses across enterprise telemetry using MITRE ATT&CK mapping.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill threat-hunter-daemon-blockint-tech
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunter
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/threat-hunter
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill threat-hunter-daemon-blockint-tech

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Proactively identify and validate attacker hypotheses across enterprise telemetry to close coverage gaps and improve SOC resilience.

Core Features & Use Cases

  • Hypothesis-driven hunts aligned to MITRE ATT&CK techniques and threat intel fusion.
  • Advanced SIEM/EDR queries, baseline and anomaly analysis, and structured hunt reporting.
  • Detection engineering feedback and handoffs to incident response for rapid containment.

Quick Start

Define a falsifiable hunt hypothesis and begin collecting relevant telemetry within a defined UTC window.

Frequently Asked Questions about threat-hunter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is hypothesis-driven threat hunting in a SOC workflow?

Hypothesis-driven threat hunting is the proactive process of defining falsifiable attacker assumptions and validating them across enterprise telemetry. It applies MITRE ATT&CK mapping and baseline anomaly analysis to close coverage gaps and improve SOC resilience.

How do I start a threat hunt using MITRE ATT&CK techniques?

To start a threat hunt, define a falsifiable hypothesis aligned to MITRE ATT&CK techniques, then collect and query relevant telemetry within a defined UTC window. This process supports baseline analysis, threat intel fusion, and structured hunt reporting.

Can threat hunting feed directly into detection engineering and incident response?

Yes, threat hunting provides direct feedback for detection engineering to improve SIEM queries. It also generates structured handoffs to incident response teams, enabling rapid containment of validated adversary threats.

What is the best way to structure threat intel fusion for SIEM queries?

The best way to structure threat intel fusion is integrating threat intelligence with baseline anomaly analysis during hypothesis validation. This approach enhances SIEM queries and maps adversary behaviors directly to MITRE ATT&CK techniques.

Does threat hunting work without a predefined hypothesis?

Hypothesis-driven threat hunting requires a predefined, falsifiable hypothesis to effectively guide telemetry collection and validation. Without this structured approach, identifying specific adversary behaviors and closing coverage gaps becomes significantly less reliable.

Why use hypothesis-driven hunting instead of standard SIEM alert monitoring?

Hypothesis-driven hunting proactively identifies attacker behaviors that existing SIEM alerts miss, closing coverage gaps. Unlike passive alert monitoring, it validates assumptions against baseline telemetry and provides structured feedback to detection engineering.