Toolverse
All skills

hunt-research-system-and-tradecraft

by OTRF

Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally

Installation

Pick a client and clone the repository into its skills directory.

Installation

Quick info

Author
OTRF
Category
Security
Views
1

About this skill

Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.

How to use

  1. Przygotuj wysokopoziomowy temat polowania (np. "Nadużycie WMI", "Nadużycie Kerberosa") — coś, co znasz tylko ogólnie, bez szczegółów technicznych.

  2. Uruchom skill i podaj temat. Skill najpierw normalizuje Twoje wejście — precyzuje platformę, system lub funkcję, którą badasz, i usuwa niejasności.

  3. Postępuj krok po kroku zgodnie z instrukcjami workflowu. Każdy krok musi być ukończony zanim przejdziesz do następnego — nie czytaj dokumentów referencyjnych ani nie wyszukuj informacji, chyba że dany krok to wyraźnie nakazuje.

  4. Skill zbiera wiedzę o normalnym działaniu systemu i znanych taktykach przeciwnika, budując ugruntowaną bazę do dalszego planowania.

  5. Otrzymasz raport końcowy zawierający kandydatów na wzorce nadużyć, kluczowe założenia i źródła — gotowy materiał do zdefiniowania konkretnej hipotezy polowania.

  6. Użyj tego raportu jako podstawy do wyboru źródeł danych i sformułowania szczegółowego planu polowania na zagrożenia.

Related skills

academic-researcher

by Shubhamsaboo

Academic research assistant for literature reviews, paper analysis, and scholarly writing.\nUse when: reviewing academic papers, conducting literature reviews, writing research summaries,\nanalyzing methodologies, formatting citations, or when user mentions academic research,

Security
1260

zendesk

by vm0-ai

Zendesk Support REST API for managing tickets, users, organizations, and support operations. Use this skill to create tickets, manage users, search, and automate customer support workflows.

Security
11100

obsidian

by gapmiss

Comprehensive guidelines for Obsidian.md plugin development including all 27 ESLint rules, TypeScript best practices, memory management, API usage (requestUrl vs fetch), UI/UX standards, and submission requirements. Use when working with Obsidian plugins, main.ts files,

Security
14111

google-analytics

by davila7

Analyze Google Analytics data, review website performance metrics, identify traffic patterns, and suggest data-driven improvements. Use when the user asks about analytics, website metrics, traffic analysis, conversion rates, user behavior, or performance optimization.

Security
1260

openapi-spec-generation

by wshobson

Generate and maintain OpenAPI 3.1 specifications from code, design-first specs, and validation patterns. Use when creating API documentation, generating SDKs, or ensuring API contract compliance.

Security
18109

software-security

by project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

Security
1678