map-environment
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Show available THRUNT threat hunting commands and artifact layout
How it fires
How this command gets triggered: by you, by Claude, or both.
/helpContext preview
What this command does when you run it.
Show available THRUNT threat hunting commands and artifact layout
name: hunt:help description: Show available THRUNT threat hunting commands and artifact layout
<objective> Display the complete THRUNT command reference.
Output ONLY the reference content below. Do NOT add:
</objective>
<execution_context> @~/.claude/thrunt-god/workflows/hunt-help.md </execution_context>
<process> Output the complete reference content from @~/.claude/thrunt-god/workflows/hunt-help.md. Display it directly with no additions or modifications. </process>
Repo: backbay-labs/thrunt-god
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
Publish a hunt as a case report, escalation, detection promotion, or leadership summary
Execute a hunt phase with parallel telemetry work, query logging, receipt generation, and optional wave targeting