Log analysis & threat hunting
SkillFiles & storageHunt for attacker activity in logs, auth, web, cloud, endpoint, with concrete queries and what to look for. Load for blue-team log/SIEM hunting, "analyze these logs", "find the attack", triage of auth/web/cloud logs, or building hunts. Signals: log files/SIEM, "what happened", IOC hunting.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Log analysis & threat hunting skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-log-analysis/SKILL.md and read by ahel’s review.
When it applies
You have logs (or a SIEM) and need to find attacker activity — during triage, IR, or proactive hunting. Pairs with each offensive skill: know the attack, hunt its footprint.
Why it works
Attacks leave patterns across log sources. Hunting hypothesis-first (pick a technique → query its signature → pivot on hits) beats scrolling. The same ATT&CK technique shows up in auth, web, cloud, and endpoint logs in characteristic ways.
Method — by source, what to look for
- Authentication: spikes of 4625/failed logins then a 4624 success (brute force →
web-rate-limit-bypass); logins from new geos/ASNs/impossible travel; new/again-enabled accounts; MFA fatigue (many prompts). - Web/proxy: bursts of 401/403/500 on one param (fuzzing), suspicious user-agents, long/encoded
query strings (SQLi/LFI/SSTI payloads), spikes to
/admin,/api,.git, requests to metadata IPs (SSRF). - Cloud (CloudTrail/Audit):
ConsoleLogin/AssumeRoleanomalies, IAM changes (CreateAccessKey,AttachUserPolicy,setIamPolicy),GetSecretValuebursts, unusual regions,iam:PassRole+ deploy (→cloud-iam-privesc). - Endpoint/process: suspicious parents (
w3wp→cmd),certutil/curldownloads, encoded PowerShell, new services/scheduled tasks (→defense-dfir-triage). - Pivot & timeline: on a hit, pivot by user/IP/host and build a timeline; correlate across sources.
Gotchas
- Baseline first — "anomalous" only means something against normal; know what normal looks like.
- Watch timezones/clock skew when correlating sources.
- Turn confirmed patterns into durable detections (→
defense-detection-sigma), don't just eyeball once.
Verify success
A concrete finding: an attacker action identified with the query that found it, pivoted to scope (accounts/hosts/timeline), and IOCs extracted for detection/containment.
References
Splunk/Elastic search docs; MITRE ATT&CK; SANS hunting; Sigma for portable detections.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
defense-log-analysis- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)pptx
Skill · anthropics
More in Files & storagedocx
Skill · anthropics
More in Files & storage