Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.
$npx -y skills add briiirussell/cybersecurity-skills --skill threat-huntingInstalls into the current project.
Run `npx skills use "https://github.com/briiirussell/cybersecurity-skills" --skill "briiirussell/cybersecurity-skills/threat-hunting"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/briiirussell/cybersecurity-skills" that are relevant to the current task. Run `npx skills add "https://github.com/briiirussell/cybersecurity-skills"` and select the relevant skills, then follow their instructions.