Skip to content
Development
Skill

/hunt-security-indicators

Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill hunt-security-indicators --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/hunt-security-indicators

Context preview

The summary Claude sees to decide when to auto-load this skill.

Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.

SKILL.md

hunt-security-indicators.SKILL.md
name: hunt-security-indicators
description: Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.

Hunt Security Indicators

Overview

Turn validated evidence into bounded queries across known data sources, then validate matches in context. Absence of matches means only that the indicator was not observed in the recorded coverage.

Read [references/hunt-record.md](references/hunt-record.md) for query and coverage fields.

Workflow

1. Define the hunt question and scope.

  • Record incident/finding, assets, identities, environments, time window, data owners, privacy constraints, and expected decision.

2. Normalize indicators and behaviors.

  • Preserve type, value, source, confidence, first/last seen, expected context, variants, and expiration.
  • Prefer behavior chains over one mutable hash/domain when telemetry supports them.

3. Inventory data sources.

  • Record endpoint/process/file, identity, DNS/network/proxy, application, cloud, email, vulnerability, and backup evidence plus retention, collection delay, and gaps.

4. Write reproducible queries.

  • Record platform/tool/version, exact query, normalization/timezone, filters, exclusions, and expected benign matches.

5. Validate matches.

  • Correlate asset/user/time/process/parent/path/signer/network or application context; preserve false-positive rationale.

6. Expand deliberately.

  • Pivot only from validated relations and update scope, indicators, and confidence.

7. Report coverage.

  • State searched/failed sources, earliest/latest available data, assets not covered, matches, negative results, and next response/detection action.

Output

Return hypothesis, indicators/behaviors, data coverage, queries, validated matches, false positives, gaps, pivots, and response recommendations.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.