hunting-advanced-persistent-threats

Featured

Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Hunting Advanced Persistent Threats ## When to Use Use this skill when: - Conducting proactive threat hunting sprints (typically 2–4 week cycles) based on newly published APT intelligence - A UEBA alert or anomaly detection system flags behavioral deviations warranting deeper investigation - A peer organization or ISAC sharing partner reports active APT compromise and you need to validate your own exposure **Do not use** this skill as a substitute for incident response when a confirmed breach is in progress — escalate to IR procedures (NIST SP 800-61). ## Prerequisites - EDR platform with telemetry retention (CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne) covering 30+ days - Access to MITRE ATT&CK Navigator for hypothesis development - Network flow data (NetFlow, Zeek, or Suricata logs) in a queryable SIEM - Threat hunting platform or query interface (Velociraptor, osquery fleet, or Splunk ES) ## Workflow ### Step 1: Develop Hunt Hypothesis Select a threat actor relevant to your sector using MITRE ATT&CK Groups (https://attack.mitre.org/groups/). Review the group's known TTPs mapped to ATT&CK techniques. Example hypothesis: "APT29 (Cozy Bear) uses spearphishing with ISO attachments (T1566.001) and living-off-the-land binaries (T1218) — test for unusual mshta.exe and rundll32.exe parent-child relationships." Document hypothesis using the Threat Hunting Loop framework: hypothesis → data collection → pattern analysis → response. ### Step 2: Iden...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category