Threat Detection

Use when hunting for threats in an environment, analysing IOCs, or detecting behavioural anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, and MITRE ATT&CK-mapped signal prioritisation. For active declared incidents, use `incident-response`. For cloud misconfigurations, use `cloud-security`.

tmj-90 5351d69 3.8 KB Updated

File contents

tmj-90/gaffer/tree/main/runner/skills/threat-detection commit 5351d69450

Frequently asked questions

npx skillmds@latest add tmj-90/threat-detection