Creator · Masriyan
Last updated · Sep 5, 2026
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Creator · Masriyan
Last updated · Sep 5, 2026
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Creator · Masriyan
Last updated · Sep 5, 2026
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Creator · Masriyan
Last updated · Sep 5, 2026
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Do not auto-install
Install targets
Codex install prompt
Install the "Threat Hunting & IOC Analysis" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/06-threat-hunting. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-threat-hunting-ioc-analysis","task":"Install Threat Hunting & IOC Analysis","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 64/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
Agent should check
Copy prompt
Task: Use Threat Hunting & IOC Analysis in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
LLM text format
/api/skills/masriyan-threat-hunting-ioc-analysis/install?format=text
Find alternatives
/api/skills/search?q=Threat%20Hunting%20%26%20IOC%20Analysis&limit=3
Agent prompt
Use Threat Hunting & IOC Analysis for this task. Review https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis
LLM text
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis?format=text
Install alias
/api/registry/install/masriyan-threat-hunting-ioc-analysis
Recommend
/api/registry/recommend?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Threat Hunting & IOC Analysis description: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation version: 3.0.0 author: Masriyan tags: [cybersecurity, threat-hunting, ioc, mitre-attack, threat-intelligence, sigma, detection, siem] ---
# Threat Hunting & IOC Analysis
## Purpose
Enable Claude to assist threat hunters with proactive threat detection, IOC extraction and normalization, MITRE ATT&CK mapping, hunt hypothesis generation, and converting threat intelligence into actionable detection rules across all major SIEM platforms.
---
## Activation Triggers
This skill activates when the user asks about: - Extracting IOCs from threat reports, emails, or security advisories - Mapping behaviors or TTPs to MITRE ATT&CK framework - Generating hunt hypotheses for a specific threat actor or technique - Creating Sigma rules, Splunk SPL queries, KQL, or EQL - Converting threat intelligence into SIEM detection queries - STIX/TAXII or MISP-compatible indicator formatting - ATT&CK Navigator layer creation - Threat intelligence correlation across multiple sources - Proactive threat hunting in a SIEM or EDR
---
## Prerequisites
```bash pip install requests pyyaml stix2 taxii2-client ```
**Optional platforms:** - MISP — Threat intelligence sharing platform - OpenCTI — Threat intelligence platform - YARA — Pattern matching (→ Skill 05) - Sigma CLI — Rule conversion tool - SIEM access (Splunk, Elastic, QRadar, Microsoft Sentinel)
---
## Core Capabilities
### 1. IOC Extraction & Normalization
**When the user provides a threat report, article, email, or log snippet:**
Claude performs these extraction steps:
1. **Parse all text** for indicators using pattern matching:
| IOC Type | Pattern Examples | |----------|----------------| | IPv4 | `192.0.2.1`, defanged: `192[.]0[.]2[.]1` | | IPv6 | `2001:db8::1` | | Domain | `evil.example.com`, `evil[.]example[.]com` | | URL | `hxxp://evil.com/path`, `https://malicious[.]io/c2` | | Email | `attacker@evil.com`, `phish[at]evil.com` | | MD5 | 32 hex chars | | SHA1 | 40 hex chars | | SHA256 | 64 hex chars | | CVE | `CVE-2024-XXXXX` | | ATT&CK ID | `T1059.001`, `TA0001` | | Registry Key | `HKCU\Software\...` | | File path | `C:\Windows\Temp\...`, `/tmp/...` | | Mutex | Named mutex patterns |
2. **Defang extracted indicators** — refang before use: - `hxxp://` → `http://` - `[.]` → `.` - `[at]` → `@` - `[:]` → `:`
3. **Categorize by type**: Network / File / Host / Identity / Vulnerability
4. **Score by confidence**: High (specific, sourced), Medium (inferred), Low (generic)
5. **Output in multiple formats**:
```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
**STIX 2.1 output template:** ```json { "type": "indicator", "id": "indicator--[uuid]", "created": "2025-05-28T00:00:00.000Z", "name": "Malicious IP — C2 Infrastructure", "pattern": "[ipv4-addr:value = '192.0.2.10']", "pattern_type": "stix", "valid_from": "2025-05-28T00:00:00Z", "labels": ["malicious-activity", "c2"], "confidence": 85 } ```
### 2. MITRE ATT&CK Mapping
**When the user provides TTPs, behaviors, or a malware report:**
```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk ```
**Mapping process:**
1. Analyze each behavior against ATT&CK technique descriptions 2. Map to specific Tactic → Technique → Sub-technique (T1059 → T1059.001) 3. Assign confidence level based on evidence quality
**ATT&CK Tactics Reference:** | Tactic | ID | Description | |--------|----|-------------| | Reconnaissance | TA0043 | Pre-attack information gathering | | Resource Development | TA0042 | Establishing attack resources | | Initial Access | TA0001 | Entry into target environment | | Execution | TA0002 | Running malicious code | | Persistence | TA0003 | Maintaining foothold | | Privilege Escalation | TA0004 | Gaining higher permissions | | Defense Evasion | TA0005 | Avoiding detection | | Credential Access | TA0006 | Stealing credentials | | Discovery | TA0007 | Understanding environment | | Lateral Movement | TA0008 | Moving through network | | Collection | TA0009 | Gathering data of interest | | Command & Control | TA0011 | Communicating with compromised hosts | | Exfiltration | TA0010 | Stealing data | | Impact | TA0040 | Disrupting/destroying systems |
**ATT&CK Navigator Layer format** (JSON for visualization): ```json { "name": "Threat Hunt Layer — [Threat Actor/Campaign]", "versions": {"attack": "14", "navigator": "4.9"}, "domain": "enterprise-attack", "techniques": [ { "techniqueID": "T1059.001", "color": "#ff6666", "comment": "Observed PowerShell download cradle", "enabled": true, "score": 100 } ] } ```
### 3. Hunt Hypothesis Generation
**When the user asks for hunt hypotheses:**
Use this structured hypothesis template:
```markdown ## Hunt Hypothesis — [ID]: [Short Name]
**Hypothesis Statement:** "We believe [Threat Actor/TTPs] may be present in [Environment] based on [Threat Intelligence / Recent Incidents / Industry Reports]."
**Rationale:** [Why this threat is relevant to this organization — industry, exposure, recent news]
**ATT&CK Techniques Covered:** - T1059.001 — PowerShell - T1053.005 — Scheduled Task/Job - T1021.001 — Remote Services: Remote Desktop Protocol
**Data Sources Required:** - Windows Event Logs (Security, System, PowerShell/4104) - EDR process execution telemetry - DNS query logs - Proxy/firewall logs
**Detection Logic:** [SIEM query or pseudocode]
**Success Criteria:** - POSITIVE: We find evidence of the technique → escalate to IR (Skill 07) - NEGATIVE: No evidence after thorough search → document as cleared hunt - INCONCLUSIVE: Insufficient data → identify logging gaps
**Estimated Hunt Duration:** [X hours] **Priority:** [High / Medium / Low] **Analyst:** [Name] ```
### 4. SIEM Detection Query Library
**When the user asks to build detection queries for specific techniques:**
#### Splunk SPL Queries
```spl // T1059.001 — PowerShell Execution with suspicious flags index=windows (source="WinEventLog:Microsoft-Windows-PowerShell/Operational" EventCode=4104) | search ScriptBlockText IN ("*DownloadString*", "*IEX*", "*EncodedCommand*", "*bypass*", "*WebClient*") | stats count by ComputerName, UserName, ScriptBlockText | where count > 0
// T1003.001 — LSASS Memory Dump index=windows EventCode=10 TargetImage="*lsass.exe" | where NOT (SourceImage IN ("C:\\Windows\\System32\\*", "C:\\Program Files\\*")) | table _time, SourceImage, TargetImage, GrantedAccess, CallTrace
// T1547.001 — Registry Run Key Persistence index=windows EventCode=13 TargetObject IN ("*\\Run\\*", "*\\RunOnce\\*") | where NOT (Image IN ("C:\\Windows\\System32\\*", "C:\\Windows\\SysWOW64\\*")) | table _time, ComputerName, Image, TargetObject, Details
// T1021.002 — Lateral Movement via SMB Admin Shares index=windows EventCode=5140 | where ShareName IN ("\\\\*\\ADMIN$", "\\\\*\\C$", "\\\\*\\IPC$") | stats count by SubjectUserName, IpAddress, ShareName, ObjectType | where count > 3 ```
#### Microsoft Sentinel KQL
```kql // T1110.001 — Brute Force Login Attempt SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h) | summarize FailCount=count() by TargetAccount, IpAddress=replace(@"\.", "[.]", tostring(parse_json(EventData).IpAddress)) | where FailCount > 20 | join kind=leftouter ( SecurityEvent | where EventID == 4624 | summarize SuccessCount=count() by TargetAccount ) on TargetAccount | project TargetAccount, IpAddress, FailCount, SuccessCount | where isnotnull(SuccessCount) // Brute force succeeded!
// T1190 — Exploit Public-Facing Application AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" | where action_s == "Blocked" | where ruleSetVersion_s startswith "3." | summarize count() by clientIp_s, requestUri_s, ruleId_s | where count_ > 100 | order by count_ desc ```
#### Elastic EQL
```eql // T1055 — Process Injection sequence by host.name [process where process.name : "notepad.exe" and event.type == "start"] [process where event.type == "start" and process.parent.name : "notepad.exe" and not process.name in ("conhost.exe")]
// T1566.001 — Spearphishing with attachment sequence by user.name within 5m [file where file.extension in ("doc", "xls", "pdf") and process.name : ("outlook.exe", "WINWORD.EXE")] [process where process.name : ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe")] ```
#### Sigma Rule Template
```yaml title: Suspicious PowerShell Download Cradle id: a3c2f1b4-8e9d-4a2c-b7f6-1234567890ab status: stable description: Detects PowerShell commands used to download and execute code from the internet author: Threat Hunter date: 2025/05/28 modified: 2025/05/28 references: - https://attack.mitre.org/techniques/T1059/001/ tags: - attack.execution - attack.t1059.001 - attack.defense_evasion - attack.t1027 logsource: category: ps_script product: windows definition: Script Block Logging enabled (EventID 4104) detection: selection: ScriptBlockText|contains|all: - 'DownloadString' - 'IEX' selection2: ScriptBlockText|contains: - '-EncodedCommand' - '-enc ' - '-WindowStyle Hidden' - 'Net.WebClient' - 'WebProxy' condition: selection or selection2 falsepositives: - Legitimate software installations - Administrative scripts level: high ```
### 5. Threat Intelligence Correlation
**When the user asks to correlate IOCs or identify threat actors:**
1. Cross-reference infrastructure across known campaigns: - Same registrar + similar registration dates → likely related infrastructure - IP hosting multiple C2 domains → infrastructure cluster - Certificate SAN fields → reveal connected domains
2. Map to threat actor groups: - MITRE ATT&CK Groups: https://attack.mitre.org/groups/ - VirusTotal/OpenCTI actor tracking - Mandiant / CrowdStrike / SentinelOne threat intel reports
3. Generate Threat Assessment: ```markdown ## Threat Assessment — [Campaign Name] **Threat Actor:** [APT Group / Criminal Group / Unknown] **Confidence:** [High / Medium / Low] **Motivation:** [Espionage / Financial / Hacktivism] **Targeting:** [Industries / Countries / Organization types] **Campaign IOCs:** - Infrastructure: [IPs, domains] - Malware: [Family names, hashes] - TTPs: [ATT&CK technique IDs] **Relevance to Organization:** [Why this threat is or isn't relevant] **Recommended Actions:** 1. Block IOCs in firewall/proxy 2. Hunt for T1XXX in SIEM 3. Deploy YARA rules for detection ```
---
## Script Reference
### `ioc_extractor.py` ```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
### `mitre_mapper.py` ```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk python scripts/mitre_mapper.py --actor "APT29" --output apt29_layer.json ```
---
## Skill Integration
| Condition | Adjacent Skill | |-----------|---------------| | IOCs from malware samples | ← Skill 05 (Malware Analysis) | | IOCs from IR engagement | ← Skill 07 (Incident Response) | | Feed hunting queries to SIEM | → Skill 12 (Log Analysis) | | Generate detection rules | → Skill 15 (Blue Team Defense) | | Automate response to findings | → Skill 11 (CSOC Automation) |
---
## References
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - [AT
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Threat Hunting & IOC Analysis, ready for a manual X post.
Threat Hunting & IOC Analysis: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis genera... 397 stars https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x
Listing + install path for Threat Hunting & IOC Analysis: https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting &...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis/audit)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Threat Hunting & IOC Analysis" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/06-threat-hunting. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-threat-hunting-ioc-analysis","task":"Install Threat Hunting & IOC Analysis","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 64/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
Agent should check
Copy prompt
Task: Use Threat Hunting & IOC Analysis in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
LLM text format
/api/skills/masriyan-threat-hunting-ioc-analysis/install?format=text
Find alternatives
/api/skills/search?q=Threat%20Hunting%20%26%20IOC%20Analysis&limit=3
Agent prompt
Use Threat Hunting & IOC Analysis for this task. Review https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis
LLM text
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis?format=text
Install alias
/api/registry/install/masriyan-threat-hunting-ioc-analysis
Recommend
/api/registry/recommend?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Threat Hunting & IOC Analysis description: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation version: 3.0.0 author: Masriyan tags: [cybersecurity, threat-hunting, ioc, mitre-attack, threat-intelligence, sigma, detection, siem] ---
# Threat Hunting & IOC Analysis
## Purpose
Enable Claude to assist threat hunters with proactive threat detection, IOC extraction and normalization, MITRE ATT&CK mapping, hunt hypothesis generation, and converting threat intelligence into actionable detection rules across all major SIEM platforms.
---
## Activation Triggers
This skill activates when the user asks about: - Extracting IOCs from threat reports, emails, or security advisories - Mapping behaviors or TTPs to MITRE ATT&CK framework - Generating hunt hypotheses for a specific threat actor or technique - Creating Sigma rules, Splunk SPL queries, KQL, or EQL - Converting threat intelligence into SIEM detection queries - STIX/TAXII or MISP-compatible indicator formatting - ATT&CK Navigator layer creation - Threat intelligence correlation across multiple sources - Proactive threat hunting in a SIEM or EDR
---
## Prerequisites
```bash pip install requests pyyaml stix2 taxii2-client ```
**Optional platforms:** - MISP — Threat intelligence sharing platform - OpenCTI — Threat intelligence platform - YARA — Pattern matching (→ Skill 05) - Sigma CLI — Rule conversion tool - SIEM access (Splunk, Elastic, QRadar, Microsoft Sentinel)
---
## Core Capabilities
### 1. IOC Extraction & Normalization
**When the user provides a threat report, article, email, or log snippet:**
Claude performs these extraction steps:
1. **Parse all text** for indicators using pattern matching:
| IOC Type | Pattern Examples | |----------|----------------| | IPv4 | `192.0.2.1`, defanged: `192[.]0[.]2[.]1` | | IPv6 | `2001:db8::1` | | Domain | `evil.example.com`, `evil[.]example[.]com` | | URL | `hxxp://evil.com/path`, `https://malicious[.]io/c2` | | Email | `attacker@evil.com`, `phish[at]evil.com` | | MD5 | 32 hex chars | | SHA1 | 40 hex chars | | SHA256 | 64 hex chars | | CVE | `CVE-2024-XXXXX` | | ATT&CK ID | `T1059.001`, `TA0001` | | Registry Key | `HKCU\Software\...` | | File path | `C:\Windows\Temp\...`, `/tmp/...` | | Mutex | Named mutex patterns |
2. **Defang extracted indicators** — refang before use: - `hxxp://` → `http://` - `[.]` → `.` - `[at]` → `@` - `[:]` → `:`
3. **Categorize by type**: Network / File / Host / Identity / Vulnerability
4. **Score by confidence**: High (specific, sourced), Medium (inferred), Low (generic)
5. **Output in multiple formats**:
```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
**STIX 2.1 output template:** ```json { "type": "indicator", "id": "indicator--[uuid]", "created": "2025-05-28T00:00:00.000Z", "name": "Malicious IP — C2 Infrastructure", "pattern": "[ipv4-addr:value = '192.0.2.10']", "pattern_type": "stix", "valid_from": "2025-05-28T00:00:00Z", "labels": ["malicious-activity", "c2"], "confidence": 85 } ```
### 2. MITRE ATT&CK Mapping
**When the user provides TTPs, behaviors, or a malware report:**
```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk ```
**Mapping process:**
1. Analyze each behavior against ATT&CK technique descriptions 2. Map to specific Tactic → Technique → Sub-technique (T1059 → T1059.001) 3. Assign confidence level based on evidence quality
**ATT&CK Tactics Reference:** | Tactic | ID | Description | |--------|----|-------------| | Reconnaissance | TA0043 | Pre-attack information gathering | | Resource Development | TA0042 | Establishing attack resources | | Initial Access | TA0001 | Entry into target environment | | Execution | TA0002 | Running malicious code | | Persistence | TA0003 | Maintaining foothold | | Privilege Escalation | TA0004 | Gaining higher permissions | | Defense Evasion | TA0005 | Avoiding detection | | Credential Access | TA0006 | Stealing credentials | | Discovery | TA0007 | Understanding environment | | Lateral Movement | TA0008 | Moving through network | | Collection | TA0009 | Gathering data of interest | | Command & Control | TA0011 | Communicating with compromised hosts | | Exfiltration | TA0010 | Stealing data | | Impact | TA0040 | Disrupting/destroying systems |
**ATT&CK Navigator Layer format** (JSON for visualization): ```json { "name": "Threat Hunt Layer — [Threat Actor/Campaign]", "versions": {"attack": "14", "navigator": "4.9"}, "domain": "enterprise-attack", "techniques": [ { "techniqueID": "T1059.001", "color": "#ff6666", "comment": "Observed PowerShell download cradle", "enabled": true, "score": 100 } ] } ```
### 3. Hunt Hypothesis Generation
**When the user asks for hunt hypotheses:**
Use this structured hypothesis template:
```markdown ## Hunt Hypothesis — [ID]: [Short Name]
**Hypothesis Statement:** "We believe [Threat Actor/TTPs] may be present in [Environment] based on [Threat Intelligence / Recent Incidents / Industry Reports]."
**Rationale:** [Why this threat is relevant to this organization — industry, exposure, recent news]
**ATT&CK Techniques Covered:** - T1059.001 — PowerShell - T1053.005 — Scheduled Task/Job - T1021.001 — Remote Services: Remote Desktop Protocol
**Data Sources Required:** - Windows Event Logs (Security, System, PowerShell/4104) - EDR process execution telemetry - DNS query logs - Proxy/firewall logs
**Detection Logic:** [SIEM query or pseudocode]
**Success Criteria:** - POSITIVE: We find evidence of the technique → escalate to IR (Skill 07) - NEGATIVE: No evidence after thorough search → document as cleared hunt - INCONCLUSIVE: Insufficient data → identify logging gaps
**Estimated Hunt Duration:** [X hours] **Priority:** [High / Medium / Low] **Analyst:** [Name] ```
### 4. SIEM Detection Query Library
**When the user asks to build detection queries for specific techniques:**
#### Splunk SPL Queries
```spl // T1059.001 — PowerShell Execution with suspicious flags index=windows (source="WinEventLog:Microsoft-Windows-PowerShell/Operational" EventCode=4104) | search ScriptBlockText IN ("*DownloadString*", "*IEX*", "*EncodedCommand*", "*bypass*", "*WebClient*") | stats count by ComputerName, UserName, ScriptBlockText | where count > 0
// T1003.001 — LSASS Memory Dump index=windows EventCode=10 TargetImage="*lsass.exe" | where NOT (SourceImage IN ("C:\\Windows\\System32\\*", "C:\\Program Files\\*")) | table _time, SourceImage, TargetImage, GrantedAccess, CallTrace
// T1547.001 — Registry Run Key Persistence index=windows EventCode=13 TargetObject IN ("*\\Run\\*", "*\\RunOnce\\*") | where NOT (Image IN ("C:\\Windows\\System32\\*", "C:\\Windows\\SysWOW64\\*")) | table _time, ComputerName, Image, TargetObject, Details
// T1021.002 — Lateral Movement via SMB Admin Shares index=windows EventCode=5140 | where ShareName IN ("\\\\*\\ADMIN$", "\\\\*\\C$", "\\\\*\\IPC$") | stats count by SubjectUserName, IpAddress, ShareName, ObjectType | where count > 3 ```
#### Microsoft Sentinel KQL
```kql // T1110.001 — Brute Force Login Attempt SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h) | summarize FailCount=count() by TargetAccount, IpAddress=replace(@"\.", "[.]", tostring(parse_json(EventData).IpAddress)) | where FailCount > 20 | join kind=leftouter ( SecurityEvent | where EventID == 4624 | summarize SuccessCount=count() by TargetAccount ) on TargetAccount | project TargetAccount, IpAddress, FailCount, SuccessCount | where isnotnull(SuccessCount) // Brute force succeeded!
// T1190 — Exploit Public-Facing Application AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" | where action_s == "Blocked" | where ruleSetVersion_s startswith "3." | summarize count() by clientIp_s, requestUri_s, ruleId_s | where count_ > 100 | order by count_ desc ```
#### Elastic EQL
```eql // T1055 — Process Injection sequence by host.name [process where process.name : "notepad.exe" and event.type == "start"] [process where event.type == "start" and process.parent.name : "notepad.exe" and not process.name in ("conhost.exe")]
// T1566.001 — Spearphishing with attachment sequence by user.name within 5m [file where file.extension in ("doc", "xls", "pdf") and process.name : ("outlook.exe", "WINWORD.EXE")] [process where process.name : ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe")] ```
#### Sigma Rule Template
```yaml title: Suspicious PowerShell Download Cradle id: a3c2f1b4-8e9d-4a2c-b7f6-1234567890ab status: stable description: Detects PowerShell commands used to download and execute code from the internet author: Threat Hunter date: 2025/05/28 modified: 2025/05/28 references: - https://attack.mitre.org/techniques/T1059/001/ tags: - attack.execution - attack.t1059.001 - attack.defense_evasion - attack.t1027 logsource: category: ps_script product: windows definition: Script Block Logging enabled (EventID 4104) detection: selection: ScriptBlockText|contains|all: - 'DownloadString' - 'IEX' selection2: ScriptBlockText|contains: - '-EncodedCommand' - '-enc ' - '-WindowStyle Hidden' - 'Net.WebClient' - 'WebProxy' condition: selection or selection2 falsepositives: - Legitimate software installations - Administrative scripts level: high ```
### 5. Threat Intelligence Correlation
**When the user asks to correlate IOCs or identify threat actors:**
1. Cross-reference infrastructure across known campaigns: - Same registrar + similar registration dates → likely related infrastructure - IP hosting multiple C2 domains → infrastructure cluster - Certificate SAN fields → reveal connected domains
2. Map to threat actor groups: - MITRE ATT&CK Groups: https://attack.mitre.org/groups/ - VirusTotal/OpenCTI actor tracking - Mandiant / CrowdStrike / SentinelOne threat intel reports
3. Generate Threat Assessment: ```markdown ## Threat Assessment — [Campaign Name] **Threat Actor:** [APT Group / Criminal Group / Unknown] **Confidence:** [High / Medium / Low] **Motivation:** [Espionage / Financial / Hacktivism] **Targeting:** [Industries / Countries / Organization types] **Campaign IOCs:** - Infrastructure: [IPs, domains] - Malware: [Family names, hashes] - TTPs: [ATT&CK technique IDs] **Relevance to Organization:** [Why this threat is or isn't relevant] **Recommended Actions:** 1. Block IOCs in firewall/proxy 2. Hunt for T1XXX in SIEM 3. Deploy YARA rules for detection ```
---
## Script Reference
### `ioc_extractor.py` ```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
### `mitre_mapper.py` ```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk python scripts/mitre_mapper.py --actor "APT29" --output apt29_layer.json ```
---
## Skill Integration
| Condition | Adjacent Skill | |-----------|---------------| | IOCs from malware samples | ← Skill 05 (Malware Analysis) | | IOCs from IR engagement | ← Skill 07 (Incident Response) | | Feed hunting queries to SIEM | → Skill 12 (Log Analysis) | | Generate detection rules | → Skill 15 (Blue Team Defense) | | Automate response to findings | → Skill 11 (CSOC Automation) |
---
## References
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - [AT
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Threat Hunting & IOC Analysis, ready for a manual X post.
Threat Hunting & IOC Analysis: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis genera... 397 stars https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x
Listing + install path for Threat Hunting & IOC Analysis: https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting &...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis/audit)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Threat Hunting & IOC Analysis" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/06-threat-hunting. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-threat-hunting-ioc-analysis","task":"Install Threat Hunting & IOC Analysis","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 64/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
Agent should check
Copy prompt
Task: Use Threat Hunting & IOC Analysis in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
LLM text format
/api/skills/masriyan-threat-hunting-ioc-analysis/install?format=text
Find alternatives
/api/skills/search?q=Threat%20Hunting%20%26%20IOC%20Analysis&limit=3
Agent prompt
Use Threat Hunting & IOC Analysis for this task. Review https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis
LLM text
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis?format=text
Install alias
/api/registry/install/masriyan-threat-hunting-ioc-analysis
Recommend
/api/registry/recommend?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Threat Hunting & IOC Analysis description: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation version: 3.0.0 author: Masriyan tags: [cybersecurity, threat-hunting, ioc, mitre-attack, threat-intelligence, sigma, detection, siem] ---
# Threat Hunting & IOC Analysis
## Purpose
Enable Claude to assist threat hunters with proactive threat detection, IOC extraction and normalization, MITRE ATT&CK mapping, hunt hypothesis generation, and converting threat intelligence into actionable detection rules across all major SIEM platforms.
---
## Activation Triggers
This skill activates when the user asks about: - Extracting IOCs from threat reports, emails, or security advisories - Mapping behaviors or TTPs to MITRE ATT&CK framework - Generating hunt hypotheses for a specific threat actor or technique - Creating Sigma rules, Splunk SPL queries, KQL, or EQL - Converting threat intelligence into SIEM detection queries - STIX/TAXII or MISP-compatible indicator formatting - ATT&CK Navigator layer creation - Threat intelligence correlation across multiple sources - Proactive threat hunting in a SIEM or EDR
---
## Prerequisites
```bash pip install requests pyyaml stix2 taxii2-client ```
**Optional platforms:** - MISP — Threat intelligence sharing platform - OpenCTI — Threat intelligence platform - YARA — Pattern matching (→ Skill 05) - Sigma CLI — Rule conversion tool - SIEM access (Splunk, Elastic, QRadar, Microsoft Sentinel)
---
## Core Capabilities
### 1. IOC Extraction & Normalization
**When the user provides a threat report, article, email, or log snippet:**
Claude performs these extraction steps:
1. **Parse all text** for indicators using pattern matching:
| IOC Type | Pattern Examples | |----------|----------------| | IPv4 | `192.0.2.1`, defanged: `192[.]0[.]2[.]1` | | IPv6 | `2001:db8::1` | | Domain | `evil.example.com`, `evil[.]example[.]com` | | URL | `hxxp://evil.com/path`, `https://malicious[.]io/c2` | | Email | `attacker@evil.com`, `phish[at]evil.com` | | MD5 | 32 hex chars | | SHA1 | 40 hex chars | | SHA256 | 64 hex chars | | CVE | `CVE-2024-XXXXX` | | ATT&CK ID | `T1059.001`, `TA0001` | | Registry Key | `HKCU\Software\...` | | File path | `C:\Windows\Temp\...`, `/tmp/...` | | Mutex | Named mutex patterns |
2. **Defang extracted indicators** — refang before use: - `hxxp://` → `http://` - `[.]` → `.` - `[at]` → `@` - `[:]` → `:`
3. **Categorize by type**: Network / File / Host / Identity / Vulnerability
4. **Score by confidence**: High (specific, sourced), Medium (inferred), Low (generic)
5. **Output in multiple formats**:
```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
**STIX 2.1 output template:** ```json { "type": "indicator", "id": "indicator--[uuid]", "created": "2025-05-28T00:00:00.000Z", "name": "Malicious IP — C2 Infrastructure", "pattern": "[ipv4-addr:value = '192.0.2.10']", "pattern_type": "stix", "valid_from": "2025-05-28T00:00:00Z", "labels": ["malicious-activity", "c2"], "confidence": 85 } ```
### 2. MITRE ATT&CK Mapping
**When the user provides TTPs, behaviors, or a malware report:**
```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk ```
**Mapping process:**
1. Analyze each behavior against ATT&CK technique descriptions 2. Map to specific Tactic → Technique → Sub-technique (T1059 → T1059.001) 3. Assign confidence level based on evidence quality
**ATT&CK Tactics Reference:** | Tactic | ID | Description | |--------|----|-------------| | Reconnaissance | TA0043 | Pre-attack information gathering | | Resource Development | TA0042 | Establishing attack resources | | Initial Access | TA0001 | Entry into target environment | | Execution | TA0002 | Running malicious code | | Persistence | TA0003 | Maintaining foothold | | Privilege Escalation | TA0004 | Gaining higher permissions | | Defense Evasion | TA0005 | Avoiding detection | | Credential Access | TA0006 | Stealing credentials | | Discovery | TA0007 | Understanding environment | | Lateral Movement | TA0008 | Moving through network | | Collection | TA0009 | Gathering data of interest | | Command & Control | TA0011 | Communicating with compromised hosts | | Exfiltration | TA0010 | Stealing data | | Impact | TA0040 | Disrupting/destroying systems |
**ATT&CK Navigator Layer format** (JSON for visualization): ```json { "name": "Threat Hunt Layer — [Threat Actor/Campaign]", "versions": {"attack": "14", "navigator": "4.9"}, "domain": "enterprise-attack", "techniques": [ { "techniqueID": "T1059.001", "color": "#ff6666", "comment": "Observed PowerShell download cradle", "enabled": true, "score": 100 } ] } ```
### 3. Hunt Hypothesis Generation
**When the user asks for hunt hypotheses:**
Use this structured hypothesis template:
```markdown ## Hunt Hypothesis — [ID]: [Short Name]
**Hypothesis Statement:** "We believe [Threat Actor/TTPs] may be present in [Environment] based on [Threat Intelligence / Recent Incidents / Industry Reports]."
**Rationale:** [Why this threat is relevant to this organization — industry, exposure, recent news]
**ATT&CK Techniques Covered:** - T1059.001 — PowerShell - T1053.005 — Scheduled Task/Job - T1021.001 — Remote Services: Remote Desktop Protocol
**Data Sources Required:** - Windows Event Logs (Security, System, PowerShell/4104) - EDR process execution telemetry - DNS query logs - Proxy/firewall logs
**Detection Logic:** [SIEM query or pseudocode]
**Success Criteria:** - POSITIVE: We find evidence of the technique → escalate to IR (Skill 07) - NEGATIVE: No evidence after thorough search → document as cleared hunt - INCONCLUSIVE: Insufficient data → identify logging gaps
**Estimated Hunt Duration:** [X hours] **Priority:** [High / Medium / Low] **Analyst:** [Name] ```
### 4. SIEM Detection Query Library
**When the user asks to build detection queries for specific techniques:**
#### Splunk SPL Queries
```spl // T1059.001 — PowerShell Execution with suspicious flags index=windows (source="WinEventLog:Microsoft-Windows-PowerShell/Operational" EventCode=4104) | search ScriptBlockText IN ("*DownloadString*", "*IEX*", "*EncodedCommand*", "*bypass*", "*WebClient*") | stats count by ComputerName, UserName, ScriptBlockText | where count > 0
// T1003.001 — LSASS Memory Dump index=windows EventCode=10 TargetImage="*lsass.exe" | where NOT (SourceImage IN ("C:\\Windows\\System32\\*", "C:\\Program Files\\*")) | table _time, SourceImage, TargetImage, GrantedAccess, CallTrace
// T1547.001 — Registry Run Key Persistence index=windows EventCode=13 TargetObject IN ("*\\Run\\*", "*\\RunOnce\\*") | where NOT (Image IN ("C:\\Windows\\System32\\*", "C:\\Windows\\SysWOW64\\*")) | table _time, ComputerName, Image, TargetObject, Details
// T1021.002 — Lateral Movement via SMB Admin Shares index=windows EventCode=5140 | where ShareName IN ("\\\\*\\ADMIN$", "\\\\*\\C$", "\\\\*\\IPC$") | stats count by SubjectUserName, IpAddress, ShareName, ObjectType | where count > 3 ```
#### Microsoft Sentinel KQL
```kql // T1110.001 — Brute Force Login Attempt SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h) | summarize FailCount=count() by TargetAccount, IpAddress=replace(@"\.", "[.]", tostring(parse_json(EventData).IpAddress)) | where FailCount > 20 | join kind=leftouter ( SecurityEvent | where EventID == 4624 | summarize SuccessCount=count() by TargetAccount ) on TargetAccount | project TargetAccount, IpAddress, FailCount, SuccessCount | where isnotnull(SuccessCount) // Brute force succeeded!
// T1190 — Exploit Public-Facing Application AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" | where action_s == "Blocked" | where ruleSetVersion_s startswith "3." | summarize count() by clientIp_s, requestUri_s, ruleId_s | where count_ > 100 | order by count_ desc ```
#### Elastic EQL
```eql // T1055 — Process Injection sequence by host.name [process where process.name : "notepad.exe" and event.type == "start"] [process where event.type == "start" and process.parent.name : "notepad.exe" and not process.name in ("conhost.exe")]
// T1566.001 — Spearphishing with attachment sequence by user.name within 5m [file where file.extension in ("doc", "xls", "pdf") and process.name : ("outlook.exe", "WINWORD.EXE")] [process where process.name : ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe")] ```
#### Sigma Rule Template
```yaml title: Suspicious PowerShell Download Cradle id: a3c2f1b4-8e9d-4a2c-b7f6-1234567890ab status: stable description: Detects PowerShell commands used to download and execute code from the internet author: Threat Hunter date: 2025/05/28 modified: 2025/05/28 references: - https://attack.mitre.org/techniques/T1059/001/ tags: - attack.execution - attack.t1059.001 - attack.defense_evasion - attack.t1027 logsource: category: ps_script product: windows definition: Script Block Logging enabled (EventID 4104) detection: selection: ScriptBlockText|contains|all: - 'DownloadString' - 'IEX' selection2: ScriptBlockText|contains: - '-EncodedCommand' - '-enc ' - '-WindowStyle Hidden' - 'Net.WebClient' - 'WebProxy' condition: selection or selection2 falsepositives: - Legitimate software installations - Administrative scripts level: high ```
### 5. Threat Intelligence Correlation
**When the user asks to correlate IOCs or identify threat actors:**
1. Cross-reference infrastructure across known campaigns: - Same registrar + similar registration dates → likely related infrastructure - IP hosting multiple C2 domains → infrastructure cluster - Certificate SAN fields → reveal connected domains
2. Map to threat actor groups: - MITRE ATT&CK Groups: https://attack.mitre.org/groups/ - VirusTotal/OpenCTI actor tracking - Mandiant / CrowdStrike / SentinelOne threat intel reports
3. Generate Threat Assessment: ```markdown ## Threat Assessment — [Campaign Name] **Threat Actor:** [APT Group / Criminal Group / Unknown] **Confidence:** [High / Medium / Low] **Motivation:** [Espionage / Financial / Hacktivism] **Targeting:** [Industries / Countries / Organization types] **Campaign IOCs:** - Infrastructure: [IPs, domains] - Malware: [Family names, hashes] - TTPs: [ATT&CK technique IDs] **Relevance to Organization:** [Why this threat is or isn't relevant] **Recommended Actions:** 1. Block IOCs in firewall/proxy 2. Hunt for T1XXX in SIEM 3. Deploy YARA rules for detection ```
---
## Script Reference
### `ioc_extractor.py` ```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
### `mitre_mapper.py` ```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk python scripts/mitre_mapper.py --actor "APT29" --output apt29_layer.json ```
---
## Skill Integration
| Condition | Adjacent Skill | |-----------|---------------| | IOCs from malware samples | ← Skill 05 (Malware Analysis) | | IOCs from IR engagement | ← Skill 07 (Incident Response) | | Feed hunting queries to SIEM | → Skill 12 (Log Analysis) | | Generate detection rules | → Skill 15 (Blue Team Defense) | | Automate response to findings | → Skill 11 (CSOC Automation) |
---
## References
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - [AT
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Threat Hunting & IOC Analysis, ready for a manual X post.
Threat Hunting & IOC Analysis: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis genera... 397 stars https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x
Listing + install path for Threat Hunting & IOC Analysis: https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting &...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis/audit)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Threat Hunting & IOC Analysis" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/06-threat-hunting. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-threat-hunting-ioc-analysis","task":"Install Threat Hunting & IOC Analysis","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 64/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
Agent should check
Copy prompt
Task: Use Threat Hunting & IOC Analysis in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC Analysis
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-threat-hunting-ioc-analysis/install
LLM text format
/api/skills/masriyan-threat-hunting-ioc-analysis/install?format=text
Find alternatives
/api/skills/search?q=Threat%20Hunting%20%26%20IOC%20Analysis&limit=3
Agent prompt
Use Threat Hunting & IOC Analysis for this task. Review https://www.openagentskill.com/api/skills/masriyan-threat-hunting-ioc-analysis/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting & IOC AnalysisRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis
LLM text
/api/registry/manifest/masriyan-threat-hunting-ioc-analysis?format=text
Install alias
/api/registry/install/masriyan-threat-hunting-ioc-analysis
Recommend
/api/registry/recommend?task=Use%20Threat%20Hunting%20%26%20IOC%20Analysis%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Threat Hunting & IOC Analysis description: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation version: 3.0.0 author: Masriyan tags: [cybersecurity, threat-hunting, ioc, mitre-attack, threat-intelligence, sigma, detection, siem] ---
# Threat Hunting & IOC Analysis
## Purpose
Enable Claude to assist threat hunters with proactive threat detection, IOC extraction and normalization, MITRE ATT&CK mapping, hunt hypothesis generation, and converting threat intelligence into actionable detection rules across all major SIEM platforms.
---
## Activation Triggers
This skill activates when the user asks about: - Extracting IOCs from threat reports, emails, or security advisories - Mapping behaviors or TTPs to MITRE ATT&CK framework - Generating hunt hypotheses for a specific threat actor or technique - Creating Sigma rules, Splunk SPL queries, KQL, or EQL - Converting threat intelligence into SIEM detection queries - STIX/TAXII or MISP-compatible indicator formatting - ATT&CK Navigator layer creation - Threat intelligence correlation across multiple sources - Proactive threat hunting in a SIEM or EDR
---
## Prerequisites
```bash pip install requests pyyaml stix2 taxii2-client ```
**Optional platforms:** - MISP — Threat intelligence sharing platform - OpenCTI — Threat intelligence platform - YARA — Pattern matching (→ Skill 05) - Sigma CLI — Rule conversion tool - SIEM access (Splunk, Elastic, QRadar, Microsoft Sentinel)
---
## Core Capabilities
### 1. IOC Extraction & Normalization
**When the user provides a threat report, article, email, or log snippet:**
Claude performs these extraction steps:
1. **Parse all text** for indicators using pattern matching:
| IOC Type | Pattern Examples | |----------|----------------| | IPv4 | `192.0.2.1`, defanged: `192[.]0[.]2[.]1` | | IPv6 | `2001:db8::1` | | Domain | `evil.example.com`, `evil[.]example[.]com` | | URL | `hxxp://evil.com/path`, `https://malicious[.]io/c2` | | Email | `attacker@evil.com`, `phish[at]evil.com` | | MD5 | 32 hex chars | | SHA1 | 40 hex chars | | SHA256 | 64 hex chars | | CVE | `CVE-2024-XXXXX` | | ATT&CK ID | `T1059.001`, `TA0001` | | Registry Key | `HKCU\Software\...` | | File path | `C:\Windows\Temp\...`, `/tmp/...` | | Mutex | Named mutex patterns |
2. **Defang extracted indicators** — refang before use: - `hxxp://` → `http://` - `[.]` → `.` - `[at]` → `@` - `[:]` → `:`
3. **Categorize by type**: Network / File / Host / Identity / Vulnerability
4. **Score by confidence**: High (specific, sourced), Medium (inferred), Low (generic)
5. **Output in multiple formats**:
```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
**STIX 2.1 output template:** ```json { "type": "indicator", "id": "indicator--[uuid]", "created": "2025-05-28T00:00:00.000Z", "name": "Malicious IP — C2 Infrastructure", "pattern": "[ipv4-addr:value = '192.0.2.10']", "pattern_type": "stix", "valid_from": "2025-05-28T00:00:00Z", "labels": ["malicious-activity", "c2"], "confidence": 85 } ```
### 2. MITRE ATT&CK Mapping
**When the user provides TTPs, behaviors, or a malware report:**
```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk ```
**Mapping process:**
1. Analyze each behavior against ATT&CK technique descriptions 2. Map to specific Tactic → Technique → Sub-technique (T1059 → T1059.001) 3. Assign confidence level based on evidence quality
**ATT&CK Tactics Reference:** | Tactic | ID | Description | |--------|----|-------------| | Reconnaissance | TA0043 | Pre-attack information gathering | | Resource Development | TA0042 | Establishing attack resources | | Initial Access | TA0001 | Entry into target environment | | Execution | TA0002 | Running malicious code | | Persistence | TA0003 | Maintaining foothold | | Privilege Escalation | TA0004 | Gaining higher permissions | | Defense Evasion | TA0005 | Avoiding detection | | Credential Access | TA0006 | Stealing credentials | | Discovery | TA0007 | Understanding environment | | Lateral Movement | TA0008 | Moving through network | | Collection | TA0009 | Gathering data of interest | | Command & Control | TA0011 | Communicating with compromised hosts | | Exfiltration | TA0010 | Stealing data | | Impact | TA0040 | Disrupting/destroying systems |
**ATT&CK Navigator Layer format** (JSON for visualization): ```json { "name": "Threat Hunt Layer — [Threat Actor/Campaign]", "versions": {"attack": "14", "navigator": "4.9"}, "domain": "enterprise-attack", "techniques": [ { "techniqueID": "T1059.001", "color": "#ff6666", "comment": "Observed PowerShell download cradle", "enabled": true, "score": 100 } ] } ```
### 3. Hunt Hypothesis Generation
**When the user asks for hunt hypotheses:**
Use this structured hypothesis template:
```markdown ## Hunt Hypothesis — [ID]: [Short Name]
**Hypothesis Statement:** "We believe [Threat Actor/TTPs] may be present in [Environment] based on [Threat Intelligence / Recent Incidents / Industry Reports]."
**Rationale:** [Why this threat is relevant to this organization — industry, exposure, recent news]
**ATT&CK Techniques Covered:** - T1059.001 — PowerShell - T1053.005 — Scheduled Task/Job - T1021.001 — Remote Services: Remote Desktop Protocol
**Data Sources Required:** - Windows Event Logs (Security, System, PowerShell/4104) - EDR process execution telemetry - DNS query logs - Proxy/firewall logs
**Detection Logic:** [SIEM query or pseudocode]
**Success Criteria:** - POSITIVE: We find evidence of the technique → escalate to IR (Skill 07) - NEGATIVE: No evidence after thorough search → document as cleared hunt - INCONCLUSIVE: Insufficient data → identify logging gaps
**Estimated Hunt Duration:** [X hours] **Priority:** [High / Medium / Low] **Analyst:** [Name] ```
### 4. SIEM Detection Query Library
**When the user asks to build detection queries for specific techniques:**
#### Splunk SPL Queries
```spl // T1059.001 — PowerShell Execution with suspicious flags index=windows (source="WinEventLog:Microsoft-Windows-PowerShell/Operational" EventCode=4104) | search ScriptBlockText IN ("*DownloadString*", "*IEX*", "*EncodedCommand*", "*bypass*", "*WebClient*") | stats count by ComputerName, UserName, ScriptBlockText | where count > 0
// T1003.001 — LSASS Memory Dump index=windows EventCode=10 TargetImage="*lsass.exe" | where NOT (SourceImage IN ("C:\\Windows\\System32\\*", "C:\\Program Files\\*")) | table _time, SourceImage, TargetImage, GrantedAccess, CallTrace
// T1547.001 — Registry Run Key Persistence index=windows EventCode=13 TargetObject IN ("*\\Run\\*", "*\\RunOnce\\*") | where NOT (Image IN ("C:\\Windows\\System32\\*", "C:\\Windows\\SysWOW64\\*")) | table _time, ComputerName, Image, TargetObject, Details
// T1021.002 — Lateral Movement via SMB Admin Shares index=windows EventCode=5140 | where ShareName IN ("\\\\*\\ADMIN$", "\\\\*\\C$", "\\\\*\\IPC$") | stats count by SubjectUserName, IpAddress, ShareName, ObjectType | where count > 3 ```
#### Microsoft Sentinel KQL
```kql // T1110.001 — Brute Force Login Attempt SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h) | summarize FailCount=count() by TargetAccount, IpAddress=replace(@"\.", "[.]", tostring(parse_json(EventData).IpAddress)) | where FailCount > 20 | join kind=leftouter ( SecurityEvent | where EventID == 4624 | summarize SuccessCount=count() by TargetAccount ) on TargetAccount | project TargetAccount, IpAddress, FailCount, SuccessCount | where isnotnull(SuccessCount) // Brute force succeeded!
// T1190 — Exploit Public-Facing Application AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" | where action_s == "Blocked" | where ruleSetVersion_s startswith "3." | summarize count() by clientIp_s, requestUri_s, ruleId_s | where count_ > 100 | order by count_ desc ```
#### Elastic EQL
```eql // T1055 — Process Injection sequence by host.name [process where process.name : "notepad.exe" and event.type == "start"] [process where event.type == "start" and process.parent.name : "notepad.exe" and not process.name in ("conhost.exe")]
// T1566.001 — Spearphishing with attachment sequence by user.name within 5m [file where file.extension in ("doc", "xls", "pdf") and process.name : ("outlook.exe", "WINWORD.EXE")] [process where process.name : ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe")] ```
#### Sigma Rule Template
```yaml title: Suspicious PowerShell Download Cradle id: a3c2f1b4-8e9d-4a2c-b7f6-1234567890ab status: stable description: Detects PowerShell commands used to download and execute code from the internet author: Threat Hunter date: 2025/05/28 modified: 2025/05/28 references: - https://attack.mitre.org/techniques/T1059/001/ tags: - attack.execution - attack.t1059.001 - attack.defense_evasion - attack.t1027 logsource: category: ps_script product: windows definition: Script Block Logging enabled (EventID 4104) detection: selection: ScriptBlockText|contains|all: - 'DownloadString' - 'IEX' selection2: ScriptBlockText|contains: - '-EncodedCommand' - '-enc ' - '-WindowStyle Hidden' - 'Net.WebClient' - 'WebProxy' condition: selection or selection2 falsepositives: - Legitimate software installations - Administrative scripts level: high ```
### 5. Threat Intelligence Correlation
**When the user asks to correlate IOCs or identify threat actors:**
1. Cross-reference infrastructure across known campaigns: - Same registrar + similar registration dates → likely related infrastructure - IP hosting multiple C2 domains → infrastructure cluster - Certificate SAN fields → reveal connected domains
2. Map to threat actor groups: - MITRE ATT&CK Groups: https://attack.mitre.org/groups/ - VirusTotal/OpenCTI actor tracking - Mandiant / CrowdStrike / SentinelOne threat intel reports
3. Generate Threat Assessment: ```markdown ## Threat Assessment — [Campaign Name] **Threat Actor:** [APT Group / Criminal Group / Unknown] **Confidence:** [High / Medium / Low] **Motivation:** [Espionage / Financial / Hacktivism] **Targeting:** [Industries / Countries / Organization types] **Campaign IOCs:** - Infrastructure: [IPs, domains] - Malware: [Family names, hashes] - TTPs: [ATT&CK technique IDs] **Relevance to Organization:** [Why this threat is or isn't relevant] **Recommended Actions:** 1. Block IOCs in firewall/proxy 2. Hunt for T1XXX in SIEM 3. Deploy YARA rules for detection ```
---
## Script Reference
### `ioc_extractor.py` ```bash python scripts/ioc_extractor.py --input threat_report.txt --output iocs.json python scripts/ioc_extractor.py --input report.pdf --format stix --output iocs.stix.json python scripts/ioc_extractor.py --input email.eml --defang --output iocs.csv ```
### `mitre_mapper.py` ```bash python scripts/mitre_mapper.py --input techniques.txt --output attack_map.json python scripts/mitre_mapper.py --technique T1059.001 --detection-query splunk python scripts/mitre_mapper.py --actor "APT29" --output apt29_layer.json ```
---
## Skill Integration
| Condition | Adjacent Skill | |-----------|---------------| | IOCs from malware samples | ← Skill 05 (Malware Analysis) | | IOCs from IR engagement | ← Skill 07 (Incident Response) | | Feed hunting queries to SIEM | → Skill 12 (Log Analysis) | | Generate detection rules | → Skill 15 (Blue Team Defense) | | Automate response to findings | → Skill 11 (CSOC Automation) |
---
## References
- [MITRE ATT&CK Framework](https://attack.mitre.org/) - [AT
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Threat Hunting & IOC Analysis, ready for a manual X post.
Threat Hunting & IOC Analysis: IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis genera... 397 stars https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x
Listing + install path for Threat Hunting & IOC Analysis: https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Threat Hunting &...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis/audit)
[](https://www.openagentskill.com/skills/masriyan-threat-hunting-ioc-analysis?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsPermission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness