/map-environment
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
$ npx -y skills add backbay-labs/thrunt-god --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/map-environment
Context preview
What this command does when you run it.
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Command definition
map-environment.mdname: hunt:map-environment description: Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots allowed-tools: - Read - Bash - Write - AskUserQuestion - Task
<objective> Create or refresh the environment map for this hunt program or case.
**Creates or updates:**
- `.planning/environment/ENVIRONMENT.md`
- `.planning/MISSION.md`
- `.planning/HYPOTHESES.md`
- `.planning/STATE.md`
Unknown tenants, tools, retention windows, access paths, and blind spots must remain `TBD` until the operator confirms them. Confirmed environment facts should replace existing `TBD` markers immediately; only unresolved fields should stay `TBD`.
**After this command:** Run `/hunt:shape-hypothesis` or `/hunt:plan 1`. </objective>
<execution_context> @~/.claude/thrunt-god/workflows/hunt-map-environment.md @~/.claude/thrunt-god/templates/environment-map.md </execution_context>
<process> Execute the environment-mapping workflow from @~/.claude/thrunt-god/workflows/hunt-map-environment.md. Prefer concrete environment facts over generic best practices. Preserve existing analyst notes. Default behavior is to preserve confirmed facts and leave unknown values as `TBD` rather than populating simulated environment details. Replace `TBD` only where live workspace evidence or direct operator input confirms the fact. </process>
Threat hunting command system for agentic IDEs
Repo: backbay-labs/thrunt-god
Other commands on thrunt-god.
- /help
Show available THRUNT threat hunting commands and artifact layout
Open command - /new-case
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Open command - /new-program
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
Open command - /plan
Create phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
Open command - /publish
Publish a hunt as a case report, escalation, detection promotion, or leadership summary
Open command - /run
Execute a hunt phase with parallel telemetry work, query logging, receipt generation, and optional wave targeting
Open command

