Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add meltedinhex/analyst-ai-pack --skill operationalizing-a-hunt-into-a-detectiongit clone --depth 1 https://github.com/meltedinhex/analyst-ai-packWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/operationalizing-a-hunt-into-a-detection)<a href="https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/operationalizing-a-hunt-into-a-detection"><img src="https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/operationalizing-a-hunt-into-a-detection/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/operationalizing-a-hunt-into-a-detection"><img src="https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/operationalizing-a-hunt-into-a-detection.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00075 | $0.00669 |
| Opus 5 | $0.00037 | $0.00334 |
| Sonnet 5 | $0.00015 | $0.00134 |
| Haiku 4.5 | $0.00007 | $0.00067 |
Grade A, and why
operationalizing-a-hunt-into-a-detection scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Operationalizing a Hunt Into a Detection
When to Use
- A hunt surfaced malicious activity and you want to convert the discriminating logic into a repeatable detection (Sigma) with data sources, thresholds, and a tuning plan.
- You are closing the hunt→detect loop so the finding is caught automatically next time.
Do not use this to ship a rule without a false-positive review — operationalization includes tuning. The script generates rule scaffolding, not a deployment.
Prerequisites
- The hunt's discriminating fields/values, the data source/log channel, and the mapped ATT&CK technique.
Workflow
Step 1: Specify the detection
Define the logsource (category/product), the selection (field→value(s) that discriminated true positives), optional filters, the condition, and the ATT&CK technique.
Step 2: Generate the Sigma rule
python scripts/analyst.py generate --spec detection.json --out rule.yml
Emits a valid Sigma rule (title, status, logsource, detection, condition, level, tags) from the spec.
Step 3: Plan testing and tuning
Define how to validate (replay a known-true pcap/log, atomic test) and what benign sources may cause false positives.
Step 4: Document and stage
Record the rule's intent, expected FPs, and tuning levers; stage through your detection pipeline.
Validation
- The generated rule has logsource, detection, and condition keys.
- The selection encodes the fields/values that discriminated the hunt's true positives.
- The rule is tagged with the relevant ATT&CK technique.
Pitfalls
- Encoding incidental artifacts (one host's path) instead of generalizable logic.
- Omitting filters for known-benign sources, guaranteeing alert fatigue.
- No test plan, so regressions go unnoticed.
References
- See
references/api-reference.mdfor the rule generator. - Sigma specification and ATT&CK hunting resources (linked in frontmatter).
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 87 lines · 75 tokens per session scan A 5e2b447118f7
operationalizing-a-hunt-into-a-detection is a skill published in the GitHub repository meltedinhex/analyst-ai-pack (22 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 75 tokens to every session and 669 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
detection-sigma
Generic detection rule creation and management using Sigma, the universal SIEM rule format. Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM platforms. Use when: (1) Creating detection rules for security monitoring, (2) Converting rules between SIEM platforms (Splunk, Elastic…
analyzing-malicious-pdf-with-peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
analyzing-cobalt-strike-beacon-configuration
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
analyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo and pclntab structures, recovering stripped/obfuscated function names (e.g. via GoResolver), and extracting embedded module/dependency strings and types from Go binaries. Use when analyzing a Go-language malware sample, deobfuscating a…
analyzing-malicious-pdf-with-peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. Use when triaging a suspicious PDF attachment from a phishing email, analyzing a PDF-based exploit document, or building detection signatures for weaponized PDF…
Threat Hunting & IOC Analysis
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation.