🛡️ Cyber Defense & SOC · SOC Operations
Hunt threats with falsifiable hypotheses
Structured hunts starting from TTP intelligence, producing detections or documented negatives.
advanced~45 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1Pick one TTP from intel relevant to your stack this month
- 2Write hypothesis: 'IF technique X used THEN artifacts Y visible in Z source'
- 3Verify telemetry actually covers Z before hunting (coverage map)
- 4Query broadly first, narrow on anomaly clusters
- 5Outcome A: findings → immediate detection rule + IR handoff
- 6Outcome B: negative → document coverage gap or baseline noise profile
Common Pitfalls
- ▲Hunting where logs don't exist, wasting hours
- ▲Findings living in hunt notes, never becoming detections
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-hunt-hypothesisInstall globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-hunt-hypothesis -gTags
#threat-hunting#mitre#proactivity#cyber-defense-ops#soc-operations