Building Threat Hunt Hypothesis Framework
SkillDocs & knowledgeThis skill guides an AI agent through a threat-hunting workflow. It turns threat intelligence or ATT&CK gap analysis into testable hypotheses, runs detection queries across EDR and SIEM platforms, and documents findings in a standardized hunt report. Use it when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.
Use Building Threat Hunt Hypothesis Framework in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Building Threat Hunt Hypothesis Framework and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Building Threat Hunt Hypothesis Framework skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have an EDR platform with process and network telemetry, such as CrowdStrike, MDE, or SentinelOne.
What your AI can do with it
- Formulate testable hypotheses from threat intelligence or ATT&CK gap analysis
- Identify required log sources and telemetry for each hypothesis
- Run detection queries against CrowdStrike, Defender, Splunk, Elastic, Sysmon
- Analyze and validate results, distinguishing true positives from false positives
- Correlate findings with attacker techniques and broader attack chains
- Produce a standardized hunt report with recommended actions
Getting started
- Have an EDR platform with process and network telemetry, such as CrowdStrike, MDE, or SentinelOne.
- Have a SIEM with relevant log data ingested, such as Splunk, Elastic, or Sentinel.
- Deploy Sysmon with a comprehensive configuration and enable Windows Security Event Log forwarding.
- Provide threat intelligence feeds for IOC correlation.
- Ask the agent to formulate a hypothesis and run the hunt workflow.
What this skill tells your AI
The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/building-threat-hunt-hypothesis-framework/SKILL.md and read by ahel’s review.
When to Use
- When proactively hunting for indicators of building threat hunt hypothesis framework in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept | Description |
|---|---|
| TA0001 | Initial Access |
| TA0003 | Persistence |
| TA0008 | Lateral Movement |
| TA0010 | Exfiltration |
Tools & Systems
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Intelligence-driven hunt based on APT campaign report
- Scenario 2: ATT&CK coverage gap analysis driving hypothesis creation
- Scenario 3: Anomaly-driven hypothesis from UEBA alert investigation
- Scenario 4: Situational awareness hunt based on industry sector threats
Output Format
Hunt ID: TH-BUILDI-[DATE]-[SEQ]
Technique: TA0001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
Signals
- GitHub stars
- 34k
- Forks
- 4k
- Last commit
- Aug 2026
ahel review
K1info
remote-installer-piped-to-shell (in references/api-reference.md)
Automated review, not a security audit. Ruleset v1+k2.
Others that do the same job
Questions
- What kind of tool is this?
- It is a skill that guides an AI agent through a threat-hunt workflow, from hypothesis to report.
- What does it do?
- It turns threat intelligence or ATT&CK gap analysis into testable hypotheses, runs queries across EDR and SIEM tools, and documents findings.
- What do I need before using it?
- An EDR platform with process and network telemetry, a SIEM with relevant logs, Sysmon with a comprehensive configuration, Windows Security Event Log forwarding, and threat intelligence feeds.
Advanced
- Item type
- skill
- Key
building-threat-hunt-hypothesis-framework-mukul975- Source
- github.com/mukul975/anthropic-cybersecurity-skills
github.com/mukul975/anthropic-cybersecurity-skills
Related picks
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretshandoff
Skill · mattpocock
More in Docs & knowledgecanvas-design
Skill · anthropics
More in Docs & knowledge