Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns...
Provide structured research context at the start of a threat hunt by incrementally applying only the references explicitly called for in each workflow step. This skill establishes a grounded understanding of system capabilities and adversary behaviors so downstream hunt planning reflects how the environment actually works and how it is realistically abused.
Translate the user's high-level topic into a precise research scope before any investigation begins. This step exists to remove ambiguity and establish a shared frame for system and adversary analysis.
This step is complete only when the scope is explicit and unambiguous.
Do NOT perform web searches or read reference documents during this step.
Build a grounded understanding of how the system functions under normal conditions.
Tavily:tavily-search, and do not exceed 5 total web search queries in this step.references/tavily-search-guide.md.During this step only:
references/system-internals-research-guide.md within this step ONLY.Do NOT read adversary tradecraft reference documents in this step. Do not synthesize or summarize findings.
Analyze how adversaries leverage or manipulate the system capabilities identified above.
Tavily:tavily-search, and do not exceed 5 total web search queries in this step.references/tavily-search-guide.md.During this step only:
references/adversary-tradecraft-research-guide.md within this step ONLY.Do Not read system internals reference documents in this step. Do Not synthesize or summarize findings.
Using the completed adversary tradecraft research, extract concrete abuse patterns that will guide hypothesis-driven hunting.
Porivide the list of patterns if they exist. They must be tool-agnostic and suitable for use in the next hunt-planning step.
Produce the final structured research artifact using the following documents within this step ONLY.
references/research-summary-template.md.references/research-citations-guide.md.This step is synthesis only. Do not introduce new research, assumptions, or evidence at this stage.