threat-hunting

Hunt threats across infrastructure and extract IOC data mapped to MITRE ATT&CK.

338|59|Updated May 19, 2026
One-click install
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill threat-hunting-hypnguyen1209
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunting
Source: https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/threat-hunting
Command: npx skills add https://github.com/hypnguyen1209/offensive-claude --skill threat-hunting-hypnguyen1209

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Proactively hunts for threats across the infrastructure, extracts IOC data, and aligns findings with MITRE ATT&CK to speed investigations.

Core Features & Use Cases

  • Proactive threat hunting across logs, endpoints, and network telemetry
  • IOC extraction, mapping to MITRE ATT&CK, and anomaly correlation
  • Detection rule authoring and incident response triage support

Quick Start

Activate threat-hunting to start a proactive search across logs for indicators of compromise and map findings to MITRE ATT&CK.

Frequently Asked Questions about threat-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I hunt for threats across enterprise logs and network telemetry?

Threat hunting across enterprise logs and network telemetry is performed by proactively searching for anomalies, correlating events, and extracting indicators of compromise to detect hidden threats.

What is MITRE ATT&CK mapping for incident response?

MITRE ATT&CK mapping for incident response is the process of correlating detected anomalies and extracted IOCs with known adversary techniques to speed up investigations and support triage.

How do I extract IOCs from endpoint logs for threat detection?

IOC extraction from endpoint logs for threat detection is achieved by analyzing telemetry to identify indicators of compromise, mapping them to MITRE ATT&CK, and generating detection reports.

Can I use Sigma rules for log analysis and anomaly baselining?

Sigma rules for log analysis and anomaly baselining are supported through detection rule authoring, allowing you to establish baselines and proactively hunt for threats across infrastructure logs.

What's the best way to map detected anomalies to MITRE ATT&CK techniques?

Mapping detected anomalies to MITRE ATT&CK techniques is best handled by correlating events across logs and endpoints, extracting IOC data, and aligning findings to speed investigations.

Does threat hunting support incident response triage and detection reports?

Threat hunting supports incident response triage and detection reports by extracting IOC data, mapping techniques to MITRE ATT&CK, and generating reports to guide investigation workflows.