Run a hypothesis-driven threat hunt: form a hypothesis (often from ATT&CK or threat intel), query telemetry for evidence, analyze findings, and convert results into detections. Use to proactively search for adversary activity that existing alerts may miss.
$npx -y skills add jassics/awesome-claude-security --skill threat-huntingInstalls into the current project.
Run `npx skills use "https://github.com/jassics/awesome-claude-security" --skill "jassics/awesome-claude-security/threat-hunting"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/jassics/awesome-claude-security" that are relevant to the current task. Run `npx skills add "https://github.com/jassics/awesome-claude-security"` and select the relevant skills, then follow their instructions.