Hunting Advanced Persistent Threats

Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.

theheavenlyd3mon e89d09d 4 files · 26.4 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-red/skills/Anthropic-Cybersecurity-Skills/skills/hunting-advanced-persistent-threats commit e89d09d03e

Frequently asked questions

npx skillmds add theheavenlyd3mon/hunting-advanced-persistent-threats