Guides blue-team threat hunting and detection engineering with hypotheses, SIEM queries, Sigma/YARA rules and validation.
- What it does
- This skill provides a hypothesis-driven threat hunting workflow: define a hypothesis, select data sources, run and stack SIEM queries, then convert findings into detection rules. It covers Sigma and YARA detection engineering, alert tuning and false-positive analysis, and detection validation using atomic tests or historical log replay. It produces hunting hypotheses, query logic, detection rules with false-positive notes and data-source mappings, and response playbook links.
- When to use it
- Use it for blue-team threat hunting, detection engineering, SIEM query design and validating whether existing detections fire. It also fits alert tuning and false-positive analysis, and handoffs from malware analysis or digital forensics into detection.
- Requirements
- Instructions only, no scripts. It assumes authorized access to a SIEM and endpoint data such as EDR exports, plus tools like Sigma CLI/sigmac, YARA, osquery and, for validation, Atomic Red Team in an authorized lab. It references a bundled hunting-loop document and sibling malware-analysis and digital-forensics material.