New to Claude Skills? Learn how to install them →

Threat Hunting skills

Free agent skills tagged threat hunting, ready to install into any SKILL.md-compatible agent.

Detecting NTLM Relay

mukul975

Identify NTLM relay attacks through event correlation.

Security & ComplianceintermediatePython27.6k repo

Hunting for DCOM Lateral Movement

mukul975

Detect DCOM abuse for enhanced cybersecurity.

Security & ComplianceadvancedPython · Shell27.6k repo

Hunting Bootkits in EFI

mukul975

Detect and analyze UEFI bootkits on your systems.

Security & ComplianceadvancedPython · Shell27.6k repo

Hunting SaaS SSO Token Abuse

mukul975

Detect and mitigate token replay attacks in SaaS environments.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Entra Offensive Tools

mukul975

Identify malicious activity in Microsoft Graph logs.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Evasion Techniques

mukul975

Identify adversary evasion tactics in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Implementing Velociraptor for IR Collection

mukul975

Streamline endpoint forensic artifact collection for incident response.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting EVTX with Chainsaw

mukul975

Rapidly analyze Windows event logs for threats.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting for LOLBins Execution

mukul975

Detect and analyze LOLBins in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

DNS Tunneling Detection with Zeek

mukul975

Identify covert data exfiltration via DNS queries.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting for WMI Persistence

mukul975

Detect and analyze WMI-based persistence mechanisms.

Security & ComplianceadvancedPython27.6k repo

Detecting T1548 Abuse

mukul975

Identify UAC bypass and privilege escalation attempts.

Security & ComplianceintermediatePython27.6k repo

Hunting for Suspicious Scheduled Tasks

mukul975

Identify and analyze potential persistence threats in Windows.

Security & ComplianceintermediatePython27.6k repo

Detecting Network Anomalies with Zeek

mukul975

Enhance network security with passive monitoring and anomaly detection.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting Advanced Persistent Threats

mukul975

Proactively hunt APT activity in enterprise environments.

Security & ComplianceadvancedPython27.6k repo

DNR Hunt

anthropics

Proactive threat hunting for logs and source code.

Security & ComplianceintermediatePython · Shell7k repo

YARA-X Rule Authoring

trailofbits

Create effective malware detection rules with YARA-X.

Security & ComplianceintermediatePython · Shell6.5k repo

Detecting Process Hollowing Technique

mukul975

Identify and analyze process hollowing threats effectively.

Security & ComplianceintermediatePython27.6k repo

Data Exfiltration Hunting

mukul975

Proactively detect data theft through network analysis.

Security & ComplianceintermediatePython27.6k repo

Detecting Lateral Movement with Splunk

mukul975

Hunt for adversary lateral movement using Splunk.

Security & ComplianceintermediatePython27.6k repo

Detecting DLL Sideloading Attacks

mukul975

Proactively detect DLL hijacking in enterprise environments.

Security & ComplianceintermediatePython27.6k repo

Hunting for C2 Beaconing

mukul975

Proactively detect command and control beaconing in networks.

Security & ComplianceintermediatePython27.6k repo

Building Threat Hunt Hypothesis Framework

mukul975

Systematize your threat hunting with structured hypotheses.

Security & ComplianceintermediatePython27.6k repo

Hunting For Registry Persistence

mukul975

Proactively detect Windows registry persistence mechanisms.

Security & ComplianceintermediatePython27.6k repo