threat-hunting
仓库创建 2026年5月19日最近提交 24 天前SkillHot 收录 21 天前
▸ 精选理由
把 ATT&CK 与检测规则流程化,便于构建可复用的检测能力
▸ 风险提示
涉及敏感日志与遥测数据,注意隐私与合规要求
这个 Skill 做什么
跨端点、网络与云的威胁狩猎方法与检测工程(Sigma/ATT&CK)
横向把端点、网络和云里的可疑行为“狩猎”出来,做检测规则工程与覆盖率测量。会在你需要基于假设追踪威胁、写 Sigma 规则并把检测当作代码在 CI 中发布,或按 MITRE ATT&CK 建模评估检测时用到。擅长 Windows 后渗透线索(Sysmon/ETW/LSASS/LOLBins)、网络 C2、beaconing、DNS 隧道和用 Atomic Red Team 做 purple‑team 验证。
▸ 展开 SKILL.md 英文原文
Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation
326
Stars
58
Forks
37
仓库内 Skill
+15
7 日增星
安装 / 使用
给你的 Agent 一句话(通用)
帮我安装这个 skill:https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/skills/threat-hunting/SKILL.md或 curl 直取 SKILL.md
curl -fsSL "https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/skills/threat-hunting/SKILL.md"SKILL.MD 节选查看完整文件 ↗
# Threat Hunting & Detection Engineering ## When to Activate - Hypothesis-driven hunting across endpoint, network, cloud, and identity telemetry - Writing & shipping detections (Sigma + correlation) as version-controlled code in CI - Mapping & measuring coverage against MITRE ATT&CK v18 (Detection Strategies / Analytics) - Hunting Windows post-exploitation: ETW/AMSI tampering, LSASS dumping, LOLBins, injection - Hunting C2 in encrypted traffic: JA4+/JA4X fingerprints, beaconing, DNS tunneling - Hunting cloud-identity attacks: Entra device-code/OAuth phishing, PRT theft, CloudTrail abuse - Purple-team validation: emulate ATT&CK with Atomic Red Team/Caldera, find detection gaps - Triaging EV
via SKILL·HOT · 数据来自 GitHub 公开信息 · 原文版权归作者所有