Building Threat Hunt Hypothesis Framework

SkillDocs & knowledge

This skill guides an AI agent through a threat-hunting workflow. It turns threat intelligence or ATT&CK gap analysis into testable hypotheses, runs detection queries across EDR and SIEM platforms, and documents findings in a standardized hunt report. Use it when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.

Use Building Threat Hunt Hypothesis Framework in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Building Threat Hunt Hypothesis Framework and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Building Threat Hunt Hypothesis Framework skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have an EDR platform with process and network telemetry, such as CrowdStrike, MDE, or SentinelOne.

Building Threat Hunt Hypothesis FrameworkStart free

What your AI can do with it

  • Formulate testable hypotheses from threat intelligence or ATT&CK gap analysis
  • Identify required log sources and telemetry for each hypothesis
  • Run detection queries against CrowdStrike, Defender, Splunk, Elastic, Sysmon
  • Analyze and validate results, distinguishing true positives from false positives
  • Correlate findings with attacker techniques and broader attack chains
  • Produce a standardized hunt report with recommended actions

Getting started

  1. Have an EDR platform with process and network telemetry, such as CrowdStrike, MDE, or SentinelOne.
  2. Have a SIEM with relevant log data ingested, such as Splunk, Elastic, or Sentinel.
  3. Deploy Sysmon with a comprehensive configuration and enable Windows Security Event Log forwarding.
  4. Provide threat intelligence feeds for IOC correlation.
  5. Ask the agent to formulate a hypothesis and run the hunt workflow.

What this skill tells your AI

The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/building-threat-hunt-hypothesis-framework/SKILL.md and read by ahel’s review.

When to Use

  • When proactively hunting for indicators of building threat hunt hypothesis framework in the environment
  • After threat intelligence indicates active campaigns using these techniques
  • During incident response to scope compromise related to these techniques
  • When EDR or SIEM alerts trigger on related indicators
  • During periodic security assessments and purple team exercises

Prerequisites

  • EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
  • SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
  • Sysmon deployed with comprehensive configuration
  • Windows Security Event Log forwarding enabled
  • Threat intelligence feeds for IOC correlation

Workflow

  1. Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
  2. Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
  3. Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
  4. Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
  5. Validate Findings: Distinguish true positives from false positives through contextual analysis.
  6. Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
  7. Document and Report: Record findings, update detection rules, and recommend response actions.

Key Concepts

ConceptDescription
TA0001Initial Access
TA0003Persistence
TA0008Lateral Movement
TA0010Exfiltration

Tools & Systems

ToolPurpose
CrowdStrike FalconEDR telemetry and threat detection
Microsoft Defender for EndpointAdvanced hunting with KQL
Splunk EnterpriseSIEM log analysis with SPL queries
Elastic SecurityDetection rules and investigation timeline
SysmonDetailed Windows event monitoring
VelociraptorEndpoint artifact collection and hunting
Sigma RulesCross-platform detection rule format

Common Scenarios

  1. Scenario 1: Intelligence-driven hunt based on APT campaign report
  2. Scenario 2: ATT&CK coverage gap analysis driving hypothesis creation
  3. Scenario 3: Anomaly-driven hypothesis from UEBA alert investigation
  4. Scenario 4: Situational awareness hunt based on industry sector threats

Output Format

Hunt ID: TH-BUILDI-[DATE]-[SEQ]
Technique: TA0001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]

Signals

GitHub stars
34k
Forks
4k
Last commit
Aug 2026

ahel review

  • K1info
    remote-installer-piped-to-shell (in references/api-reference.md)

Automated review, not a security audit. Ruleset v1+k2.

Questions

What kind of tool is this?
It is a skill that guides an AI agent through a threat-hunt workflow, from hypothesis to report.
What does it do?
It turns threat intelligence or ATT&CK gap analysis into testable hypotheses, runs queries across EDR and SIEM tools, and documents findings.
What do I need before using it?
An EDR platform with process and network telemetry, a SIEM with relevant logs, Sysmon with a comprehensive configuration, Windows Security Event Log forwarding, and threat intelligence feeds.
Advanced
Item type
skill
Key
building-threat-hunt-hypothesis-framework-mukul975
Source
github.com/mukul975/anthropic-cybersecurity-skills