hunting-for-spearphishing-indicators
Analyzes telemetry and logs to detect spearphishing campaigns.
Install
mkdir -p .claude/skills/hunting-for-spearphishing-indicators && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/16810" && unzip -o skill.zip -d .claude/skills/hunting-for-spearphishing-indicators && rm skill.zipInstalls to .claude/skills/hunting-for-spearphishing-indicators
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Hunt for spearphishing campaign indicators across email logs, endpointKey capabilities
- →Formulate threat-hunting hypotheses
- →Identify relevant data sources for validation
- →Execute queries against SIEM and EDR platforms
- →Analyze query results for anomalies
- →Validate findings to distinguish true positives
- →Correlate activity to broader attack chains
How it works
The skill guides the user through a workflow of formulating hypotheses, identifying data sources, executing queries on SIEM/EDR, analyzing results, validating findings, and correlating activity to detect spearphishing indicators.
Inputs & outputs
When to use hunting-for-spearphishing-indicators
- →Hunting for initial access attempts
- →Analyzing email security logs
- →Investigating T1566 techniques
- →Validating security threats
About this skill
Hunting For Spearphishing Indicators
When to Use
- When proactively hunting for indicators of hunting for spearphishing indicators in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept | Description |
|---|---|
| T1566.001 | Spearphishing Attachment |
| T1566.002 | Spearphishing Link |
| T1566.003 | Spearphishing via Service |
Tools & Systems
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Macro-enabled Excel executing PowerShell downloader
- Scenario 2: HTML smuggling delivering ISO with LNK payload
- Scenario 3: Credential harvesting link as SharePoint notification
- Scenario 4: QR code phishing in PDF attachment
Output Format
Hunt ID: TH-HUNTIN-[DATE]-[SEQ]
Technique: T1566.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
When not to use it
- →When EDR or SIEM platforms are not available
- →When Sysmon is not deployed or Windows Security Event Logs are not forwarded
- →When threat intelligence feeds for IOC correlation are not accessible
Prerequisites
Limitations
- →Requires specific EDR and SIEM platforms to be in place
- →Depends on Sysmon deployment and Windows Security Event Log forwarding
- →Relies on threat intelligence feeds for effective IOC correlation
How it compares
This skill provides a structured, step-by-step methodology for proactively hunting for spearphishing indicators across various security platforms, unlike reactive alert-driven investigations.
Compared to similar skills
hunting-for-spearphishing-indicators side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| hunting-for-spearphishing-indicators (this skill) | 0 | 2mo | Review | Advanced |
| protocol-reverse-engineering | 9 | 7mo | Review | Advanced |
| equilateral-agents | 5 | 9mo | No flags | Intermediate |
| secops-triage | 4 | 7mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by megawesley2015-lang
View all by megawesley2015-lang →You might also like
protocol-reverse-engineering
wshobson
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
equilateral-agents
Equilateral-AI
22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).
secops-triage
Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
netflows
BrownFineSecurity
Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.
azure-bgp
benchflow-ai
Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.
secops-investigate
Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.