Loading...
Loading...
Guides proactive threat hunting for advanced SOC—hypothesis-driven hunt campaigns, advanced SIEM/query workflows, baseline and anomaly analysis, MITRE ATT&CK–aligned techniques, threat intel fusion, detection engineering feedback, and hunt reporting with IR handoff. Use for threat hunting, proactive hunt, hypothesis-driven detection, advanced SOC, hunt campaign, detection engineering, MITRE ATT&CK hunt, anomaly hunting—not routine SOC alert triage (soc-analyst), declared incident command (incident-responder), adversary simulation campaigns (red-team-specialist), disk forensics acquisition (digital-forensics-analyst), authorized pentest (penetration-tester), or binary RE lab work (reverse-engineer).
npx skill4agent add daemon-blockint-tech/agentic-enteprises-skill threat-huntersoc-analystincident-responderred-team-specialistdigital-forensics-analystpenetration-testerreverse-engineercloud-security-engineercybersecurity| Need | Skill |
|---|---|
| SOC alert triage, playbooks, false-positive closure | |
| Declared incident command, containment, stakeholder IR | |
| Security program, hunt program governance, board narrative | |
| Cloud audit log hunts, org-wide cloud telemetry gaps | |
| Purple team / adversary simulation and detection validation | |
| Authorized pentest findings as hunt hypotheses | |
| Forensic acquisition after hunt confirms major incident | |
| Sample-driven static/dynamic analysis from hunt artifacts | |
| CTI briefs, IOC/TTP packages, actor/campaign analysis | |
soc-analystthreat-hunterincident-responderreferences/hypothesis_and_hunt_planning.mdreferences/siem_query_and_telemetry.mdreferences/threat_intel_and_attck_mapping.mdreferences/detection_engineering_feedback.mdincident-respondersoc-analystreferences/hunt_reporting_and_handoff.mdreferences/threat_hunter_scope.mdreferences/hypothesis_and_hunt_planning.mdreferences/siem_query_and_telemetry.mdreferences/threat_intel_and_attck_mapping.mdreferences/detection_engineering_feedback.mdreferences/hunt_reporting_and_handoff.mdincident-responder