HU

hunt-data-source-identification

Map security hunt hypotheses to relevant data sources.

Install

mkdir -p .claude/skills/hunt-data-source-identification && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4556" && unzip -o skill.zip -d .claude/skills/hunt-data-source-identification && rm skill.zip

Installs to .claude/skills/hunt-data-source-identification

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Identify relevant security data sources that could capture the behavior defined in a structured hunt hypothesis. Use this skill after the hunt focus has been defined to translate investigative intent into candidate telemetry sources using existing platform catalogs. This skill supports hunt planning by reasoning over available schemas and metadata before analytics development or query execution.
398 charsno explicit “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Intermediate

Key capabilities

  • Mapping attack behaviors to telemetry sources
  • Performing semantic search on telemetry catalogs
  • Translating hypotheses to observable log types
  • Structuring data identification for hunting

How it works

Uses a semantic matching engine to align abstract threat indicators with available schema descriptions and metadata.

Inputs & outputs

You give it
Structured hunt hypothesis
You get back
List of relevant candidate data tables

When to use hunt-data-source-identification

  • Identify data sources for a hunt hypothesis
  • Plan telemetry requirements for threat detection
  • Map adversary behavior to platform logs
  • Prepare hunt planning for security audits

About this skill

Identify Relevant Data Sources

This skill translates a structured hunt hypothesis into a set of candidate data sources that could realistically capture the behavior being investigated.

It is executed after the hunt focus has been defined and before analytics are written or queries are executed.

Workflow

  • You MUST complete each step in order and MUST NOT proceed until the current step is complete.
  • You MUST NOT read reference documents unless the current step explicitly instructs you to do so.
  • You MUST NOT write queries or perform data analysis in this skill.
  • Do NOT introduce new research about system internals or adversary tradecraft.

Step 1: Interpret the Hunt Focus

Understand the investigative intent defined by the hunt hypothesis.

  • Review the structured hunt hypothesis.
  • Identify:
    • The attack behavior being investigated
    • The platform context (e.g., Windows, Cloud)
    • The type of activity that must be observable (e.g., configuration changes, execution, authentication)
  • Do NOT infer specific data tables yet.

This step is complete when the expected observable activity is clearly understood at a conceptual level. Do NOT read reference documents during this step.

Step 2: Discover Candidate Data Sources

Identify data sources that could capture the expected activity.

  • Use MS Sentinel.search_tables to perform a semantic search over the telemetry catalog.
  • Search using:
    • The hunt hypothesis
    • Descriptions of the expected behavior
    • Relevant platform or activity keywords
  • Do NOT search for data sources using specific table names.
  • Review returned table descriptions and schemas to assess relevance.

This step reasons over schemas and metadata available in the data lake catalog and does not assert that data is currently flowing, complete, or retained.

Do NOT write queries or validate detections in this step. Do NOT read reference documents during this step.

Step 3: Refine and Validate Relevance

Narrow the list of candidate data sources.

  • Select tables that:
    • Are plausibly able to capture the expected behavior
    • Expose schema elements aligned with the observable activity
  • Explicitly note:
    • Conceptual coverage limitations based on available schemas
    • Planning-level assumptions inferred from table names, descriptions, and schema semantics
  • Surface gaps where expected categories of telemetry do not appear to be represented.

Step 4: Produce Data Source Summary

Produce a final summary using the following documents within this step ONLY.

  • Structure the output using references/data-source-summary-template.md.
  • Do NOT include queries, filters, validation steps, or execution logic.

When not to use it

  • Initial hypothesis generation
  • Performing live incident response or remediation

Prerequisites

Access to security telemetry catalogDefined hunt hypothesis

Limitations

  • Limited to mapped platform schemas
  • Cannot identify missing telemetry not present in catalog

How it compares

It ensures technical alignment between hunt planning and telemetry capabilities before any queries are written.

Compared to similar skills

hunt-data-source-identification side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
hunt-data-source-identification (this skill)17moNo flagsIntermediate
protocol-reverse-engineering96moReviewAdvanced
equilateral-agents59moNo flagsIntermediate
secops-triage47moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

hunt-analytics-generation

OTRF

Generate query-agnostic analytics that model adversary behavior by translating hunt investigative intent into analytic definitions grounded in schema semantics. This skill is used to define how behavior should manifest in data before query execution or validation, and works best when informed by system internals, adversary tradecraft, a structured hunt focus, and suggested data sources.

12

hunt-blueprint-generation

OTRF

Assemble a complete hunt blueprint by consolidating outputs from prior hunt planning skills into a single, structured plan for execution. Use this skill after system and tradecraft research, hunt focus definition, data source identification, and analytics generation have been completed. This skill is synthesis and packaging only and must not introduce new research, assumptions, or analytics.

15

hunt-focus-definition

OTRF

Define a focused hunt hypothesis by synthesizing completed system internals and adversary tradecraft research. Use this skill after research has been completed to narrow a high-level hunt topic into a single, concrete attack pattern with clear investigative intent. This skill produces a structured, testable hypothesis and should be used before selecting data sources, defining environment scope, or developing analytics.

13

hunt-research-system-and-tradecraft

OTRF

Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.

13

You might also like

protocol-reverse-engineering

wshobson

Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.

973

equilateral-agents

Equilateral-AI

22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).

564

secops-triage

google

Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.

424

netflows

BrownFineSecurity

Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.

18

azure-bgp

benchflow-ai

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.

26

secops-investigate

google

Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.

17

Search skills

Search the agent skills registry