Retour au classement

OTRF/ThreatHunter-Playbook

Python

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

threat-huntingsysmonhunting-campaignshypothesishuntingdfirhuntermitre-attack-dbmitre
Croissance des étoiles
Étoiles
4.6k
Forks
855
Croissance hebdomadaire
Issues
6
2k4k
avr. 2017mai 2020juin 2023juil. 2026
ArtefactsPyPIpip install threathunter-playbook
README

The Threat Hunter Playbook

Binder License: MIT Twitter Open_Threat_Research Community Open Source Love

The Threat Hunter Playbook is a community-driven, open source project focused on documenting how threat hunters think, plan, and reason before, during, and after a hunt. The project captures adversary tradecraft, detection logic, and supporting resources in a structured way to make threat hunting more effective and repeatable. All hunt documents follow the structure of MITRE ATT&CK, organizing post-compromise behavior into tactical groups and expressing it through interactive Jupyter notebooks. These notebooks combine markdown, analytics, datasets, and validation queries, allowing hunts to be treated as executable documents that preserve intent and reasoning—not just results—and can be run locally or remotely using pre-recorded security datasets and BinderHub.

With recent advances in Generative AI, the project has entered a transformation phase focused on augmenting threat hunting workflows across planning, execution, and reporting. Rather than replacing existing practices, the goal is to integrate AI in a way that reinforces structure and intent throughout the lifecycle. As a first step, the project incorporates solutions such as Agent Skills to capture hunting knowledge as explicit workflows, providing clear guidance, templates, and references. Agent Skills guide reasoning and decision making, refining broad inputs into structured, testable hunt artifacts and laying the groundwork for deeper AI augmentation over time.

Docs: https://threathunterplaybook.com/

Goals

  • Document and share how threat hunters plan, reason, and structure hunts across the full lifecycle.
  • Expedite the development of hunt techniques and hypotheses grounded in system behavior and adversary tradecraft.
  • Provide reusable workflows, templates, and references that support consistent hunt planning and analysis.
  • Enable validation and experimentation using pre-recorded security datasets, locally or through cloud-based environments.
  • Enable AI-augmented threat hunting workflows with human oversight.
  • Accelerate learning and knowledge sharing through open source, community-driven resources.

Threat Hunting as a Framework

The Threat Hunter Playbook is organized around a simple, repeatable lifecycle grounded in shared understanding of system behavior, adversary tradecraft, and environmental context. The framework captures how hunts are planned, executed, and documented, emphasizing structure and reasoning over ad hoc investigation.

At a high level, the framework consists of three stages:

  • Plan — Build context and analytic intent by defining the behavior being hunted, assumptions, expected activity, and how that behavior should manifest in telemetry.
  • Execute — Apply the plan by running queries, analyzing results, and iterating as assumptions are tested and new context emerges.
  • Report — Capture outcomes regardless of results, including findings, false positives, visibility gaps, and follow-on actions.

While the framework spans the full hunting lifecycle, the work in this repository currently concentrates on formalizing the planning stage, where intent, assumptions, and analytic structure are established before execution begins.

Agent Skills for Threat Hunting

To support this evolution, the project introduces Agent Skills as a way to express threat hunting workflows in a form that both humans and AI agents can follow consistently. Agent Skills package knowledge as explicit workflows with ordered steps, templates, and references, allowing agents to apply structure where it is most valuable.

In this project, Agent Skills are used to generate a structured hunt blueprint through workflows such as:

  • Researching system internals and adversary tradecraft
  • Defining a focused hunt hypothesis
  • Identifying relevant data sources
  • Developing analytics that model adversary behavior
  • Assembling a complete hunt blueprint for execution

For a detailed walkthrough and example of these workflows in action, see the accompanying blog post.

https://blog.openthreatresearch.com/evolving-the-threat-hunter-playbook-planning-hunts-with-agent-skills/

Authors

Acknowledgements

Dépôts similaires
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

PythonPyPIApache License 2.0ai-agentsclaude-code
mahipal.engineer/Anthropic-Cybersecurity-Skills/
26.3k3.2k
OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

CGNU General Public License v2.0securityids
suricata.io
6.5k1.7k
MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

PHPPackagistGNU Affero General Public License v3.0mispthreat-sharing
misp-project.org
6.4k1.6k
elceef/dnstwist

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

PythonPyPIApache License 2.0phishingtyposquatting
dnstwist.it
5.7k849
SwiftOnSecurity/sysmon-config

Sysmon configuration file template with default high-quality event tracing

sysmonthreatintel
5.6k1.9k
Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

ShellOthercase-managementcyber-security
securityonion.net
4.8k666
0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

awesomeawesome-list
0x4d31.github.io/awesome-threat-detection/
4.7k756
intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

PythonPyPIGNU Affero General Public License v3.0security-toolspython
intelowlproject.github.io
4.6k649
pedramamini/awesome-yara

A curated list of awesome YARA rules, tools, and people.

Otheryara-rulesyara-signatures
4.2k552
alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

PythonPyPIGNU General Public License v3.0malwarevirustotal
github.com/alexandreborges/malwoverview
4k535
Cyb3rWard0g/HELK

The Hunting ELK

Jupyter NotebookGNU General Public License v3.0huntingelasticsearch
3.9k690
InQuest/awesome-yara

A curated list of awesome YARA rules, tools, and people.

Otheryara-rulesyara-signatures
3.7k507