Skip to content
Back to skills

Cyber Threat Hunting

ASecurity

Conducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.

  • 571 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 24, 2026
development

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-threat-hunting --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Threat Hunting?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Threat Hunting
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-threat-hunting-f3aef8c1/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-threat-hunting-f3aef8c1)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cyber-threat-hunting
guardrail: true
description: Conducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.
metadata:
  triggers:
    files: []
    keywords:
      - threat hunting
      - hunt hypothesis
      - hunting query
      - negative conclusion
      - suspicious activity hunt
      - telemetry gap
---
# Cyber Threat Hunting

## **Priority: P0 (CRITICAL)**
Preserve provenance and bound every conclusion to authorized evidence.

## Structure
Input: falsifiable hypothesis, behavior, entities, scope, sources, window, expected signal, stop condition. Process: define positive/negative observations; normalize without overwriting originals; test narrowest evidence; correlate by entity/time; record gaps and alternatives. Output: status, cited evidence, bounded conclusion, limitations, owner.

## Rules
- Active collection or network operations require `cyber-authorization`, documented scope, and runtime-proven controls; unsupported or missing scope blocks execution.
- Use controlled synthetic/offline fixtures. Preserve query/version, fixture provenance, retention, clock, identity, and source limitations.
- Status is `confirmed`, `suspected`, `false-positive`, `blocked`, or `not-tested`; only cited evidence supports a status.
- “No evidence found in the examined dataset/time window” is bounded negative evidence, never proof of no compromise.
- Include engagement/scope reference; skill/version/source; observation time; status; evidence references; limitations; accountable owner. Reuse shared skill IDs.

## Anti-Patterns
- Never call an empty or incomplete dataset clean.
- Never treat one ambiguous hit as confirmed compromise.
- Never collect live telemetry before authorization or invent hunt metrics.

## References (lazy, primary)
- MITRE ATT&CK data sources: https://attack.mitre.org/datasources/
- NIST SP 800-86 evidence handling: https://doi.org/10.6028/NIST.SP.800-86
- Reuse `cyber-authorization`, `cyber-evidence`, `cyber-framework-mapping`.

Files in this skill

  • SKILL.md2.2 KB
  • evals/evals.json3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…