skill
threat-hunting
Use when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting (Sysmon/ETW/LSASS/LOLBins), network C2 hunting (JA4+, beaconing, DNS tunneling), cloud-identity hunting, Atomic Red Team purple-team validation
Description as published by the maintainer. Source
- active
active — Most recent push to the repository was 2026-07-03.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 337 | Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. | cumulative, all time | GitHub | |
| Last commit | 2026-07-03 | Most recent push to the containing repository. It may reflect work on a different skill in the same collection. | point in time | GitHub | |
| repository status | active | The repository holding this skill exists and is not archived. | as of fetch | GitHub |
Will this work with your setup?
No harness stated by the author and no install path convention detected. Compatibility is untested.
We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.
The skill definition lives at skills/threat-hunting/SKILL.md in https://github.com/hypnguyen1209/offensive-claude.
Where to get it
Related, by what their authors tagged them
-
hypnguyen1209-offensive-claude-active-directory-attack
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when attacking a Windows Active Directory domain — Kerberos roasting/delegation, coercion + NTLM/Kerberos relay (CV…
-
hypnguyen1209-offensive-claude-ai-agent-redteam
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when red-teaming an agentic AI / LLM application — indirect & zero-click prompt injection, MCP tool poisoning, pers…
-
hypnguyen1209-offensive-claude-ai-security
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/v…
-
hypnguyen1209-offensive-claude-browser-exploitation
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when building a client-side browser exploit — V8/JSC JIT type confusion to renderer R/W, V8 heap-sandbox escape, re…
-
hypnguyen1209-offensive-claude-cicd-supply-chain
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution, c…
-
hypnguyen1209-offensive-claude-cloud-security
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT…
-
hypnguyen1209-offensive-claude-coding-mastery
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, a…
-
hypnguyen1209-offensive-claude-container-k8s-escape
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when breaking out of a container or escalating inside Kubernetes — runc/BuildKit CVEs, privileged/capability/cgroup…
-
hypnguyen1209-offensive-claude-crypto-analysis
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD m…
-
hypnguyen1209-offensive-claude-edr-evasion
— last commit 2026-07-03, shares exploit-development, offensive-security, redteam
Use when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection…
These share tags the maintainers applied themselves, such as exploit-development, offensive-security, redteam. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
Also from hypnguyen1209
-
hypnguyen1209-offensive-claude-engagement-flow
— last commit 2026-07-03
Use when starting, planning, or running a multi-phase pentest or red-team engagement — to sequence the Cyber Kill Chain…
-
hypnguyen1209-offensive-claude-engagement-memory
— last commit 2026-07-03
Use when recalling prior techniques at recon/weaponize, or recording a confirmed finding at report — cross-engagement p…
-
hypnguyen1209-offensive-claude-exploit-development
— last commit 2026-07-03
Use when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT…
-
hypnguyen1209-offensive-claude-finding-discipline
— last commit 2026-07-03
Use when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONFIR…
-
hypnguyen1209-offensive-claude-incident-response
— last commit 2026-07-03
Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3…
-
hypnguyen1209-offensive-claude-initial-access
— last commit 2026-07-03
Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-c…
-
hypnguyen1209-offensive-claude-malware-analysis
— last commit 2026-07-03
Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/…
-
hypnguyen1209-offensive-claude-mobile-pentest
— last commit 2026-07-03
Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 C…
-
hypnguyen1209-offensive-claude-network-attack
— last commit 2026-07-03
Use when attacking a network or moving laterally — L2/L3 poisoning (LLMNR/mDNS, ARP/DHCP, mitm6), coercion + NTLM relay…
-
hypnguyen1209-offensive-claude-opsec-discipline
— last commit 2026-07-03
Use when about to take any outward or offensive action (request, payload, persistence, lateral movement, exfil, or feed…
How the author describes it
Topics the maintainer set on GitHub: claude-code, claude-code-skills, exploit-development, offensive-security, redteam.
Bring your own setup
We take apart real AI setups every week and show what broke, what cost too much, and what the trace actually said. If you run agents on real work, that is where the useful conversation is.
Join ZBS AI Practice Lab