Skip to content
Back to skills

Hunt Security Indicators

ASecurity

Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
ai-agentssecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add gaelic-ghost/socket --skill hunt-security-indicators --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hunt Security Indicators?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hunt Security Indicators
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gaelic-ghost-hunt-security-indicators/badge)](https://www.skillsdirectory.com/skills/gaelic-ghost-hunt-security-indicators)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hunt-security-indicators
description: Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.
---

# Hunt Security Indicators

## Overview

Turn validated evidence into bounded queries across known data sources, then validate matches in context. Absence of matches means only that the indicator was not observed in the recorded coverage.

Read [references/hunt-record.md](references/hunt-record.md) for query and coverage fields.

## Workflow

1. Define the hunt question and scope.
   - Record incident/finding, assets, identities, environments, time window, data owners, privacy constraints, and expected decision.
2. Normalize indicators and behaviors.
   - Preserve type, value, source, confidence, first/last seen, expected context, variants, and expiration.
   - Prefer behavior chains over one mutable hash/domain when telemetry supports them.
3. Inventory data sources.
   - Record endpoint/process/file, identity, DNS/network/proxy, application, cloud, email, vulnerability, and backup evidence plus retention, collection delay, and gaps.
4. Write reproducible queries.
   - Record platform/tool/version, exact query, normalization/timezone, filters, exclusions, and expected benign matches.
5. Validate matches.
   - Correlate asset/user/time/process/parent/path/signer/network or application context; preserve false-positive rationale.
6. Expand deliberately.
   - Pivot only from validated relations and update scope, indicators, and confidence.
7. Report coverage.
   - State searched/failed sources, earliest/latest available data, assets not covered, matches, negative results, and next response/detection action.

## Output

Return hypothesis, indicators/behaviors, data coverage, queries, validated matches, false positives, gaps, pivots, and response recommendations.

Files in this skill

  • SKILL.md1.9 KB
  • agents/openai.yaml247 B
  • references/hunt-record.md618 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…