Skip to content
Back to skills

Cyber Threat Hunting

ASecurity

Status: **blocked** Assumption: this is a live DNS threat-hunting query; no entities, time window, query text, or engagement/scope reference were supplied. I cannot run it because: - DNS collection is disabled, so the dataset is unavailable/incomplete. - No `cyber-authorization` or engagement/scope reference exists. - Active collection or network operations require documented scope and runtime-proven controls. No query was executed, and no evidence or hunt metrics were generated. This is **no...

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
development

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-threat-hunting --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Threat Hunting?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Threat Hunting
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-threat-hunting-2b4ead97/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-threat-hunting-2b4ead97)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Status: **blocked**

Assumption: this is a live DNS threat-hunting query; no entities, time window, query text, or engagement/scope reference were supplied.

I cannot run it because:

- DNS collection is disabled, so the dataset is unavailable/incomplete.
- No `cyber-authorization` or engagement/scope reference exists.
- Active collection or network operations require documented scope and runtime-proven controls.

No query was executed, and no evidence or hunt metrics were generated. This is **not** a clean result and does not support a negative conclusion.

To proceed:

1. Provide the engagement/scope reference and authorization under `cyber-authorization`.
2. Enable DNS telemetry for the approved scope and window.
3. Preserve the original records and provenance under `cyber-evidence`, including query/version, fixture or source provenance, retention, clock, identity, and source limitations.
4. Run the narrowest query, correlate by entity and time, and map findings through `cyber-framework-mapping` using MITRE ATT&CK data sources.
5. Record status as `confirmed`, `suspected`, `false-positive`, `blocked`, or `not-tested`, with evidence references, limitations, observation time, skill/version/source, and an accountable owner.

Observation time: **2026-09-22, Asia/Ho_Chi_Minh**.  
Evidence references: **none**.  
Owner: **unassigned hunt owner/requester**.

Files in this skill

  • eval-1.baseline.md482 B
  • eval-1.with-skill.md1.5 KB
  • eval-2.baseline.md179 B
  • eval-2.with-skill.md1.3 KB
  • eval-3.baseline.md175 B
  • eval-3.with-skill.md446 B
  • trigger-1.md127 B
  • trigger-2.md157 B
  • trigger-3.md146 B
  • trigger-4.md134 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…