Threat Hunting

Autonomous threat hunting using the PEAK framework (Prepare → Execute → Act). Executes hypothesis-driven, intelligence-driven, and baseline hunts against CrowdStrike NG-SIEM. Produces hunt reports, detection backlogs, and visibility gap reports. Use when proactively hunting for threats, validating detection coverage, or responding to new threat intelligence.

willwebster5 Updated

File contents

willwebster5/agent-skills/tree/main/plugins/crowdstrike-threat-hunting/skills/threat-hunting commit fab7facb2d

Frequently asked questions

npx skillmds@latest add willwebster5/threat-hunting