What problem does it solve?
This Skill removes the manual overhead of turning threat reports, advisories, and logs into usable hunting intelligence, so analysts can move faster from raw evidence to actionable defense.
Core Features & Use Cases
- IOC Extraction and Normalization: Pulls indicators such as IPs, domains, hashes, URLs, emails, and file paths from text and normalizes or defangs them for safe sharing.
- MITRE ATT&CK Mapping: Converts observed behaviors and techniques into ATT&CK tactics, techniques, sub-techniques, and Navigator layers for consistent analysis.
- Detection and Hunt Engineering: Produces hunt hypotheses, SIEM queries, and Sigma-style detection logic for platforms such as Splunk, Elastic, and Microsoft Sentinel.
- Use Case: A threat hunter can feed in a security advisory, extract indicators, map the attacker behavior, and generate a focused hunt plan with measurable outcomes.
Quick Start
Ask the skill to analyze a threat report, extract the indicators of compromise, map the behaviors to MITRE ATT&CK, and draft a hunt hypothesis with detection logic.