Hunting Threats

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk, KQL, and Elastic. Use when proactively searching for undetected compromise, validating an intel report against your environment, or converting a hunch into a repeatable hunt.

trilwu 671aa67 13.6 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/hunting-threats commit 671aa67cb2

Frequently asked questions

npx skillmds add trilwu/hunting-threats