HU

hunting-for-spearphishing-indicators

Analyzes telemetry and logs to detect spearphishing campaigns.

Install

mkdir -p .claude/skills/hunting-for-spearphishing-indicators && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/16810" && unzip -o skill.zip -d .claude/skills/hunting-for-spearphishing-indicators && rm skill.zip

Installs to .claude/skills/hunting-for-spearphishing-indicators

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Hunt for spearphishing campaign indicators across email logs, endpoint
70 charsno explicit “when” trigger
Advanced

Key capabilities

  • Formulate threat-hunting hypotheses
  • Identify relevant data sources for validation
  • Execute queries against SIEM and EDR platforms
  • Analyze query results for anomalies
  • Validate findings to distinguish true positives
  • Correlate activity to broader attack chains

How it works

The skill guides the user through a workflow of formulating hypotheses, identifying data sources, executing queries on SIEM/EDR, analyzing results, validating findings, and correlating activity to detect spearphishing indicators.

Inputs & outputs

You give it
Threat intelligence, ATT&CK gap analysis, EDR/SIEM alerts
You get back
Hunt ID, technique, host, user, evidence, risk level, confidence, and recommended action

When to use hunting-for-spearphishing-indicators

  • Hunting for initial access attempts
  • Analyzing email security logs
  • Investigating T1566 techniques
  • Validating security threats

About this skill

Hunting For Spearphishing Indicators

When to Use

  • When proactively hunting for indicators of hunting for spearphishing indicators in the environment
  • After threat intelligence indicates active campaigns using these techniques
  • During incident response to scope compromise related to these techniques
  • When EDR or SIEM alerts trigger on related indicators
  • During periodic security assessments and purple team exercises

Prerequisites

  • EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
  • SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
  • Sysmon deployed with comprehensive configuration
  • Windows Security Event Log forwarding enabled
  • Threat intelligence feeds for IOC correlation

Workflow

  1. Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
  2. Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
  3. Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
  4. Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
  5. Validate Findings: Distinguish true positives from false positives through contextual analysis.
  6. Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
  7. Document and Report: Record findings, update detection rules, and recommend response actions.

Key Concepts

ConceptDescription
T1566.001Spearphishing Attachment
T1566.002Spearphishing Link
T1566.003Spearphishing via Service

Tools & Systems

ToolPurpose
CrowdStrike FalconEDR telemetry and threat detection
Microsoft Defender for EndpointAdvanced hunting with KQL
Splunk EnterpriseSIEM log analysis with SPL queries
Elastic SecurityDetection rules and investigation timeline
SysmonDetailed Windows event monitoring
VelociraptorEndpoint artifact collection and hunting
Sigma RulesCross-platform detection rule format

Common Scenarios

  1. Scenario 1: Macro-enabled Excel executing PowerShell downloader
  2. Scenario 2: HTML smuggling delivering ISO with LNK payload
  3. Scenario 3: Credential harvesting link as SharePoint notification
  4. Scenario 4: QR code phishing in PDF attachment

Output Format

Hunt ID: TH-HUNTIN-[DATE]-[SEQ]
Technique: T1566.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]

When not to use it

  • When EDR or SIEM platforms are not available
  • When Sysmon is not deployed or Windows Security Event Logs are not forwarded
  • When threat intelligence feeds for IOC correlation are not accessible

Prerequisites

EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)Sysmon deployed with complete configurationWindows Security Event Log forwarding enabled

Limitations

  • Requires specific EDR and SIEM platforms to be in place
  • Depends on Sysmon deployment and Windows Security Event Log forwarding
  • Relies on threat intelligence feeds for effective IOC correlation

How it compares

This skill provides a structured, step-by-step methodology for proactively hunting for spearphishing indicators across various security platforms, unlike reactive alert-driven investigations.

Compared to similar skills

hunting-for-spearphishing-indicators side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
hunting-for-spearphishing-indicators (this skill)02moReviewAdvanced
protocol-reverse-engineering97moReviewAdvanced
equilateral-agents59moNo flagsIntermediate
secops-triage47moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

protocol-reverse-engineering

wshobson

Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.

973

equilateral-agents

Equilateral-AI

22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).

564

secops-triage

google

Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.

424

netflows

BrownFineSecurity

Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.

18

azure-bgp

benchflow-ai

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.

26

secops-investigate

google

Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.

17

Search skills

Search the agent skills registry