{"enrichment":{"faq":[{"a":"Threat-hunting is a skill for conducting hypothesis-driven threat investigations across Windows endpoints, network traffic, and cloud identity. It equips you with Sigma-based detection rules, MITRE ATT&CK mapping, and offline triage tools to hunt threats, engineer detections, and validate coverage gaps using purple-team emulation.","q":"What is threat-hunting and what does it cover?"},{"a":"Threat-hunting provides detection strategies for Windows post-exploitation techniques including LSASS dumping, ETW/AMSI tampering, LOLBin abuse, and process injection. You'll learn to use Sysmon telemetry, EVTX triage tools like Hayabusa and Chainsaw, and process tree anomaly detection to identify these attacks.","q":"How does threat-hunting help detect Windows post-exploitation?"},{"a":"Threat-hunting teaches you to build and deploy Sigma rules for Windows endpoint detection, map them to MITRE ATT&CK techniques, and integrate them into detection-as-code CI pipelines. You'll learn to triage EVTX logs and correlate endpoint telemetry with network signals for comprehensive threat visibility.","q":"What sigma rules and windows endpoint detection methods does threat-hunting teach?"},{"a":"Threat-hunting covers C2 hunting via JA4 fingerprinting for malware identification, beaconing detection using tools like RITA, and DNS tunneling analysis. These techniques let you hunt command-and-control activity even in encrypted network traffic without decryption.","q":"How can threat-hunting detect C2 beaconing in encrypted traffic?"},{"a":"Yes. Threat-hunting includes cloud identity attack hunting focused on device-code phishing, PRT token theft, and CloudTrail abuse detection. You'll learn to identify Entra ID compromise patterns and validate detections across hybrid cloud-identity environments.","q":"Does threat-hunting address cloud identity attack hunting?"},{"a":"Threat-hunting teaches purple-team validation using atomic red team emulation to measure ATT&CK coverage gaps. You'll map detections to the coverage matrix via ATT&CK Navigator and refine your detection engineering based on real adversary behavior simulation.","q":"How does threat-hunting validate detection coverage?"}],"shadow_tags":["purple-teaming","detection-engineering","threat-intel-ops","endpoint-forensics","network-traffic-analysis","identity-security","infrastructure-as-code","adversary-emulation"],"summary_rewrite":"Threat Hunting equips you to conduct hypothesis-driven threat investigations across Windows endpoints, network traffic, and cloud identity using Sigma-based detection rules, MITRE ATT&CK mapping, and offline triage tools. Execute C2 hunting via JA4 fingerprinting and beaconing analysis, detect post-exploitation techniques like LSASS dumping and LOLBin abuse, and validate detection coverage with purple-team emulation."},"files":[{"bytes":9436,"path":"skills/threat-hunting/SKILL.md","sha256":"76328bc8b7b946e60b3e14c1404416894ce3a5e78e5f5e594de34263d67b0a1b","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/threat-hunting/302cb93b/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/threat-hunting","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/threat-hunting","md":"https://skillfed.io/hypnguyen1209/offensive-claude/threat-hunting.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"threat-hunting","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/malware-analysis"},{"id":"hypnguyen1209/offensive-claude/incident-response"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"Aradotso/mcp-skills/security-detections-mcp"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"Aradotso/security-skills/security-detections-mcp"},{"id":"telagod/code-abyss/detecting-and-responding"},{"id":"hypnguyen1209/offensive-claude/network-attack"},{"id":"AgentSecOps/SecOpsAgentKit/detection-sigma"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"threat-hunting"},"version":"302cb93b"}
