⚡AgentSkills
🛡️ Cyber Defense & SOC · SOC Operations

Hunt threats with falsifiable hypotheses

Structured hunts starting from TTP intelligence, producing detections or documented negatives.

advanced~45 minSOC AnalystsDetection EngineersThreat Hunters

Steps

  1. 1Pick one TTP from intel relevant to your stack this month
  2. 2Write hypothesis: 'IF technique X used THEN artifacts Y visible in Z source'
  3. 3Verify telemetry actually covers Z before hunting (coverage map)
  4. 4Query broadly first, narrow on anomaly clusters
  5. 5Outcome A: findings → immediate detection rule + IR handoff
  6. 6Outcome B: negative → document coverage gap or baseline noise profile

Common Pitfalls

  • ▲Hunting where logs don't exist, wasting hours
  • ▲Findings living in hunt notes, never becoming detections

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-hunt-hypothesis
Install globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-hunt-hypothesis -g

Tags

#threat-hunting#mitre#proactivity#cyber-defense-ops#soc-operations

Related skills

Enrichment order, true/false-positive calls with evidence, and escalation criteria applied identically every shift.

🛡️ Cyber Defense & SOC·~25m

Inventory what you can see versus what attacks require, closing blind spots deliberately.

🛡️ Cyber Defense & SOC·~35m