CtrlK
BlogDocsLog inGet started
Tessl Logo

building-threat-hunt-hypothesis-framework

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma) and documents findings in a standardized hunt report. Use when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/building-threat-hunt-hypothesis-framework/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill reads as a clean, well-organized overview with a sensible seven-step hunt workflow and a concrete output template, but it stays at the descriptive level: no example queries or commands in the body, no feedback loops for refuted hypotheses, and — most critically — none of the six bundle files (references, scripts, assets/template.md) are ever referenced, so the detailed content is undiscoverable. It is a solid skeleton that needs its flesh wired in via explicit pointers and a few concrete executable examples.

Suggestions

Add one or two concrete example queries (e.g., a Splunk SPL or Defender KQL hunting query) under 'Execute Queries', or link to references/workflows.md where the per-platform queries already live.

Reference the bundle files explicitly in the body — e.g., 'Detailed per-platform workflows: see [references/workflows.md](references/workflows.md)', 'Hypothesis builder: scripts/agent.py', 'Hunt report template: assets/template.md' — so the existing detail content is discoverable from SKILL.md.

Add feedback loops to the workflow: what to do when a hypothesis is refuted or queries return no data (refine the hypothesis, expand data sources/time window, re-run), and a checkpoint before documenting that findings were correlated across at least two data sources.

DimensionReasoningScore

Conciseness

The body is table-driven and lean overall, but the 'Key Concepts' table ('TA0001 | Initial Access', 'TA0003 | Persistence') restates standard ATT&CK tactic mappings Claude already knows, and the 'When to Use' bullet 'indicators of building threat hunt hypothesis framework' is templated filler. These are minor trim candidates, matching 'efficient; minor instances of over-explanation'.

4 / 5

Actionability

'Execute Queries: Run detection queries against SIEM and EDR platforms' and 'Analyze Results: Examine query results for anomalies' are high-level directions with no actual SPL/KQL example, command, or script invocation anywhere in the body — the concrete queries live in references/workflows.md and scripts/ but are never surfaced. The Output Format template is the only concretely executable artifact, so guidance is present but incomplete ('some concrete guidance but incomplete; missing key details'), not the minimal-hints level of a 2.

3 / 5

Workflow Clarity

The seven steps (Formulate → Identify Data Sources → Execute → Analyze → Validate → Correlate → Document) are clearly sequenced and 'Validate Findings: Distinguish true positives from false positives' is a named validation step. However, there are no feedback loops or checkpoints — no guidance on iterating when a hypothesis is refuted, queries return no data, or a data source is missing — so checkpoints are implicit rather than explicit, matching 'steps listed but validation gaps'.

3 / 5

Progressive Disclosure

The body itself is well-sectioned (When to Use, Prerequisites, Workflow, Tools, Scenarios, Output Format), but it never mentions any of the provided bundle files — references/workflows.md (with the actual platform queries), references/api-reference.md, references/standards.md, scripts/agent.py, scripts/process.py, and assets/template.md are all invisible to a reader of SKILL.md. The structure is better than 'minimal' (not a 2), but the complete absence of links/pointers to existing detail files falls short of the clear signaled navigation of a 4 or 5.

3 / 5

Total

13

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a strong description: it states what the skill does across the full hunt lifecycle with named platforms, and gives an explicit 'Use when...' trigger clause for both intel- and anomaly-driven hunts. The only deductions are minor — a few missing natural trigger synonyms and slight overlap risk with adjacent incident-response/detection-engineering skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'turns threat intelligence and ATT&CK gap analysis into testable hypotheses', 'executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma)', 'documents findings in a standardized hunt report' — with named tools, matching 'multiple specific concrete actions; comprehensive coverage'. It does not fall to 4 because coverage spans the full lifecycle (build, execute, validate, document) rather than having minor gaps.

5 / 5

Completeness

It explicitly answers both parts: the 'what' is 'Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them... and documents findings', and the 'when' is 'Use when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.' — a concrete trigger clause, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Natural terms a user would say are well covered: 'threat hunt', 'threat intelligence', 'proactive threat hunt', 'scoping compromise', 'intel- or anomaly-driven', plus tool names. A few common variations are missing (e.g., 'threat hunting' as a noun phrase, 'IOC', 'purple team'), so it fits 'good keyword coverage; a few natural terms missing' rather than the comprehensive synonym/extension coverage of a 5.

4 / 5

Distinctiveness Conflict Risk

The proactive threat-hunting niche with explicit tool list (CrowdStrike, Splunk, Velociraptor, Sigma) is largely distinct from generic IR or detection-engineering skills. Minor overlap risk remains with incident-response and detection-rule skills because 'scoping compromise' and Sigma-rule mentions could plausibly arise in those contexts, so 'mostly distinct; minor overlap risk' fits better than the minimal-conflict level 5.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.