threat-hunting

Generate hypotheses and artifacts for MITRE ATT&CK-aligned threat hunting.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill threat-hunting-drupadsachania
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunting
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/threat-hunting
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill threat-hunting-drupadsachania

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Proactive threat hunting workflow enables defenders to anticipate and identify adversary activity before it triggers incidents, reducing dwell time and improving mean time to detect.

Core Features & Use Cases

  • Structured hypothesis generation, data collection, detection logic, investigation, and reporting across multiple platforms.
  • Integrates MITRE ATT&CK and custom threat-hunting maturity frameworks to guide hunt campaigns.
  • Use cases include hypothesis-driven hunts, telemetry quality validation, and automated artifact generation for detection engineering.

Quick Start

Run threat-hunting on a phase to begin structured hunting with hypothesis generation.

Frequently Asked Questions about threat-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a proactive threat hunt using MITRE ATT&CK?

Proactive threat hunting uses hypothesis-driven investigations aligned with MITRE ATT&CK to identify adversary activity in telemetry before incidents occur, reducing dwell time and improving mean time to detect.

What's the best way to generate hypotheses for threat hunting campaigns?

Hypothesis generation for threat hunting campaigns is structured phase-by-phase, starting with hypothesis creation, followed by data collection, detection logic, investigation, and reporting across multiple platforms.

Can I use threat hunting workflows for red-team exercises?

Threat hunting workflows support both enterprise security operations and red-team exercises needing hypothesis-driven investigations, applicable to phase-based workflows from hypothesis generation to reporting.

How does threat hunting integrate with detection engineering?

Threat hunting integrates with detection engineering through automated artifact generation, producing outputs from investigations that can be used to build and validate detection logic in your SIEM.

Does threat hunting validate SIEM telemetry quality?

Telemetry quality validation is a core use case of threat hunting, ensuring that your SIEM data collection supports effective hypothesis-driven hunts and reliable adversary activity detection.

How do I start a structured threat hunt without prior incident data?

Run threat hunting on a specific phase to begin structured hunting with hypothesis generation, allowing you to proactively anticipate and identify adversary activity in telemetry before incidents trigger.