New to Claude Skills? Learn how to install them →

Threat Hunting skills

Free agent skills tagged threat hunting, ready to install into any SKILL.md-compatible agent.

Hunting for Suspicious Scheduled Tasks

mukul975

Identify and analyze potential persistence threats in Windows.

Security & ComplianceintermediatePython27.6k repo

Detecting NTLM Relay

mukul975

Identify NTLM relay attacks through event correlation.

Security & ComplianceintermediatePython27.6k repo

Detecting DCSync Attack

mukul975

Identify and respond to DCSync attacks in Active Directory.

Security & ComplianceintermediatePython27.6k repo

Hunting for LOLBins Execution

mukul975

Detect and analyze LOLBins in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Hunting for Living-off-the-Land Binaries

mukul975

Proactively detect malicious use of trusted system binaries.

Security & ComplianceintermediatePython27.6k repo

Generating Forensic Timelines

mukul975

Transform Windows event logs into actionable forensic timelines.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting EVTX with Chainsaw

mukul975

Rapidly analyze Windows event logs for threats.

Security & ComplianceintermediatePython · Shell27.6k repo

Fleet Hunting with Velociraptor

mukul975

Conduct fleet-wide threat hunts with deep endpoint visibility.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting T1055 Process Injection

mukul975

Identify and analyze process injection techniques using Sysmon.

Security & ComplianceintermediatePython27.6k repo

Hunting for WMI Persistence

mukul975

Detect and analyze WMI-based persistence mechanisms.

Security & ComplianceadvancedPython27.6k repo

Hunting for Beaconing

mukul975

Detect command-and-control beaconing in network traffic.

Security & ComplianceintermediatePython27.6k repo

Implementing Velociraptor for IR Collection

mukul975

Streamline endpoint forensic artifact collection for incident response.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Credential Dumping

mukul975

Identify and respond to credential theft in your environment.

Security & ComplianceintermediatePython27.6k repo

Detecting Entra Offensive Tools

mukul975

Identify malicious activity in Microsoft Graph logs.

Security & ComplianceintermediatePython · Shell27.6k repo

DNS Tunneling Detection with Zeek

mukul975

Identify covert data exfiltration via DNS queries.

Security & ComplianceintermediatePython · Shell27.6k repo

Detecting Evasion Techniques

mukul975

Identify adversary evasion tactics in endpoint logs.

Security & ComplianceintermediatePython27.6k repo

Hunting SaaS SSO Token Abuse

mukul975

Detect and mitigate token replay attacks in SaaS environments.

Security & ComplianceintermediatePython · Shell27.6k repo

Deploying Osquery for Endpoint Monitoring

mukul975

Real-time endpoint monitoring with SQL-based queries.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting for DCOM Lateral Movement

mukul975

Detect DCOM abuse for enhanced cybersecurity.

Security & ComplianceadvancedPython · Shell27.6k repo

Detecting T1548 Abuse

mukul975

Identify UAC bypass and privilege escalation attempts.

Security & ComplianceintermediatePython27.6k repo

Hunting Bootkits in EFI

mukul975

Detect and analyze UEFI bootkits on your systems.

Security & ComplianceadvancedPython · Shell27.6k repo

Detecting Network Anomalies with Zeek

mukul975

Enhance network security with passive monitoring and anomaly detection.

Security & ComplianceintermediatePython · Shell27.6k repo

Hunting Advanced Persistent Threats

mukul975

Proactively hunt APT activity in enterprise environments.

Security & ComplianceadvancedPython27.6k repo

YARA-X Rule Authoring

trailofbits

Create effective malware detection rules with YARA-X.

Security & ComplianceintermediatePython · Shell6.5k repo