secops-hunt - Proactive Threat Hunting for Security Operations
Expert guidance for proactive threat hunting to identify undetected threats
Tags
Updated: 2026-02-11Capabilities
Typical Inputs
Typical Outputs
What this skill does
- check indicator matches
- search security events
- query UDM data
- list SOAR cases
- lookup entity information
- translate UDM queries
Inputs
- GTI collection ID
- MITRE technique IDs
- time frame hours
- target scope query
- IOC list
- search terms
Outputs
- markdown report file
- SOAR case comment
- case update
- suspicious activity findings
Requirements
- SIEM access
- security event database
- UDM query capability
- SOAR integration
