threat-hunting

Generate ABLE-based hunting hypotheses from intelligence data into OpenTide TVM/DOM/MDR constructs.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill threat-hunting-opentidehq
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-hunting
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/threat-hunting
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill threat-hunting-opentidehq

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides a rigorous, ABLE-based framework to generate structured hunting hypotheses from intelligence and translate validated hunts into OpenTide content.

Core Features & Use Cases

  • ABLE-based hypothesis creation, scoring, and anti-pattern checks to ensure rigor.
  • End-to-end hypothesis lifecycle from intelligence intake to DOM/MDR integration and TVM updates.
  • Data-gap analysis and evidence mapping to telemetry sources to guide platform-specific hunting.
  • OpenTide content conversion pathways, enabling hunt findings to drive detection engineering and TVM narratives.

Quick Start

Use a sourced intelligence cue to create an ABLE-complete hypothesis following the lifecycle steps.

Frequently Asked Questions about threat-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate structured threat hunting hypotheses from cyber threat intelligence?

ABLE-based threat hunting structures each hypothesis with A/B/L/E components, documented source references, data gaps, and anti-pattern checks to ensure analytical rigor before mapping evidence to telemetry sources.

What is the best way to track evidence and data gaps during a threat hunt?

Evidence tracking and data-gap analysis map collected telemetry to specific hunting hypotheses, identifying missing data sources to guide platform-specific hunting and ensure comprehensive coverage across the intelligence lifecycle.

How does hypothesis-driven threat hunting integrate with vulnerability management workflows?

Validated hunting hypotheses integrate with vulnerability management workflows by mapping evidence, data gaps, and scoring into OpenTide TVM, DOM, and MDR constructs to update threat narratives and drive detection engineering.

Can I convert threat hunting findings into detection engineering content?

Threat hunting findings convert into detection engineering content through OpenTide content conversion pathways, enabling validated hunt results to directly drive detection rules and TVM narrative updates across the platform.

Do I need sourced intelligence to start hypothesis-driven threat hunting?

Sourced intelligence cues are required to initiate hypothesis-driven threat hunting, serving as the entry point for the ABLE-complete hypothesis lifecycle from intelligence intake through post-hunt analysis and integration.

What are the limitations of hypothesis-based threat hunting without anti-pattern checks?

Hypothesis-based threat hunting without anti-pattern checks lacks analytical rigor, risking unstructured investigations that fail to document data gaps, source references, and telemetry mappings required for OpenTide integration.