Map security hunt hypotheses to relevant data sources.
Install
mkdir -p .claude/skills/hunt-data-source-identification && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4556" && unzip -o skill.zip -d .claude/skills/hunt-data-source-identification && rm skill.zipInstalls to .claude/skills/hunt-data-source-identification
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Identify relevant security data sources that could capture the behavior defined in a structured hunt hypothesis. Use this skill after the hunt focus has been defined to translate investigative intent into candidate telemetry sources using existing platform catalogs. This skill supports hunt planning by reasoning over available schemas and metadata before analytics development or query execution.Key capabilities
- →Mapping attack behaviors to telemetry sources
- →Performing semantic search on telemetry catalogs
- →Translating hypotheses to observable log types
- →Structuring data identification for hunting
How it works
Uses a semantic matching engine to align abstract threat indicators with available schema descriptions and metadata.
Inputs & outputs
When to use hunt-data-source-identification
- →Identify data sources for a hunt hypothesis
- →Plan telemetry requirements for threat detection
- →Map adversary behavior to platform logs
- →Prepare hunt planning for security audits
About this skill
Identify Relevant Data Sources
This skill translates a structured hunt hypothesis into a set of candidate data sources that could realistically capture the behavior being investigated.
It is executed after the hunt focus has been defined and before analytics are written or queries are executed.
Workflow
- You MUST complete each step in order and MUST NOT proceed until the current step is complete.
- You MUST NOT read reference documents unless the current step explicitly instructs you to do so.
- You MUST NOT write queries or perform data analysis in this skill.
- Do NOT introduce new research about system internals or adversary tradecraft.
Step 1: Interpret the Hunt Focus
Understand the investigative intent defined by the hunt hypothesis.
- Review the structured hunt hypothesis.
- Identify:
- The attack behavior being investigated
- The platform context (e.g., Windows, Cloud)
- The type of activity that must be observable (e.g., configuration changes, execution, authentication)
- Do NOT infer specific data tables yet.
This step is complete when the expected observable activity is clearly understood at a conceptual level. Do NOT read reference documents during this step.
Step 2: Discover Candidate Data Sources
Identify data sources that could capture the expected activity.
- Use
MS Sentinel.search_tablesto perform a semantic search over the telemetry catalog. - Search using:
- The hunt hypothesis
- Descriptions of the expected behavior
- Relevant platform or activity keywords
- Do NOT search for data sources using specific table names.
- Review returned table descriptions and schemas to assess relevance.
This step reasons over schemas and metadata available in the data lake catalog and does not assert that data is currently flowing, complete, or retained.
Do NOT write queries or validate detections in this step. Do NOT read reference documents during this step.
Step 3: Refine and Validate Relevance
Narrow the list of candidate data sources.
- Select tables that:
- Are plausibly able to capture the expected behavior
- Expose schema elements aligned with the observable activity
- Explicitly note:
- Conceptual coverage limitations based on available schemas
- Planning-level assumptions inferred from table names, descriptions, and schema semantics
- Surface gaps where expected categories of telemetry do not appear to be represented.
Step 4: Produce Data Source Summary
Produce a final summary using the following documents within this step ONLY.
- Structure the output using
references/data-source-summary-template.md. - Do NOT include queries, filters, validation steps, or execution logic.
When not to use it
- →Initial hypothesis generation
- →Performing live incident response or remediation
Prerequisites
Limitations
- →Limited to mapped platform schemas
- →Cannot identify missing telemetry not present in catalog
How it compares
It ensures technical alignment between hunt planning and telemetry capabilities before any queries are written.
Compared to similar skills
hunt-data-source-identification side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| hunt-data-source-identification (this skill) | 1 | 7mo | No flags | Intermediate |
| protocol-reverse-engineering | 9 | 6mo | Review | Advanced |
| equilateral-agents | 5 | 9mo | No flags | Intermediate |
| secops-triage | 4 | 7mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by OTRF
View all by OTRF →You might also like
protocol-reverse-engineering
wshobson
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
equilateral-agents
Equilateral-AI
22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).
secops-triage
Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
netflows
BrownFineSecurity
Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.
azure-bgp
benchflow-ai
Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.
secops-investigate
Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.