Threat Hunting

Plan, run, and write up hypothesis-driven threat hunts (PEAK / TaHiTI style): turn a threat report, an ATT&CK technique, a coverage gap, an anomaly, or "something feels off" into a testable hypothesis with data sources, queries, expected benign volume, an analysis technique (stacking, prevalence, baselining, clustering, sequencing, outliers), success criteria, and hand-offs. Use it whenever someone says "hunt for", "go look for", "is anyone doing X in our environment", "what should we hunt this week", "build a hunt from this report", "stack these values", "what is rare here", "baseline this data source", or hands over a CSV/JSONL export and asks what stands out. Also use it when a report or a purple-team result implies behaviour that no alert covers, even if nobody says the word hunt.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/threat-hunting commit 84757f858a

Frequently asked questions

npx skillmds@latest add ftrout/threat-hunting