smithery.ai

hunt-apt

Hunt for a specific APT/threat actor in your environment. Use when you have a threat actor name or GTI collection ID and want to search for their TTPs and IOCs. Gathers intelligence from GTI, searches SIEM for IOCs and TTP-based indicators, and documents findings.

First seen Apr 29, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 4,224 B
  • docs SUMMARY.md 280 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

APT Threat Hunt Skill

Proactively hunt for TTPs and IOCs associated with a specific Advanced Persistent Threat (APT) group based on threat intelligence.

Inputs

  • THREATACTORID - GTI Collection ID or name of the target APT group
  • HUNTTIMEFRAMEHOURS - Lookback period (default: 168 = 7 days)
  • (Optional) TARGETSCOPEQUERY - UDM query to narrow scope
  • (Optional) HUNT_HYPOTHESIS - Specific hypothesis guiding the hunt
  • (Optional) HUNTCASEID - SOAR case for tracking

Workflow

Step 1: Identify Actor & Gather Intelligence

If starting with a name:

gti-mcp.search_threat_actors(query="APT_NAME")

Then gather comprehensive intelligence:

gti-mcp.get_collection_report(id=THREAT_ACTOR_ID)
gti-mcp.get_collection_mitre_tree(id=THREAT_ACTOR_ID)
gti-mcp.get_collection_timeline_events(id=THREAT_ACTOR_ID)

Extract associated IOCs:

gti-mcp.get_entities_related_to_a_collection(id=THREAT_ACTOR_ID, relationship_name="files")
gti-mcp.get_entities_related_to_a_collection(id=THREAT_ACTOR_ID, relationship_name="domains")
gti-mcp.get_entities_related_to_a_collection(id=THREAT_ACTOR_ID, relationship_name="urls")

Store as GTIIOCLIST.

Step 2: Check SIEM IOC Matches

secops-mcp.get_ioc_matches(hours_back=HUNT_TIMEFRAME_HOURS)

Correlate results with GTIIOCLIST.

Step 3: IOC-Based SIEM Search

For each IOC type in GTIIOCLIST, construct and execute UDM queries:

secops-mcp.search_security_events(
    text="UDM query for IOC",
    hours_back=HUNT_TIMEFRAME_HOURS
)

Document both positive and negative results → IOCSEARCHFINDINGS.

Step 4: TTP-Based SIEM Search

Based on MITRE techniques from Step 1:

  • Use gti-mcp.getthreatintel(query="MITRE technique details") for detection ideas
  • Formulate TTP-specific UDM queries
  • Execute searches over the timeframe
  • Combine with TARGETSCOPEQUERY if provided

Document results → TTPSEARCHFINDINGS.

Step 5: Enrich Findings

If hits found (IOCSEARCHFINDINGS or TTPSEARCHFINDINGS):

For each found IOC or entity:

secops-mcp.lookup_entity(entity_value=FOUND_ITEM)
gti-mcp.get_..._report(identifier=FOUND_ITEM)

Step 6: Check Related Cases

Use /find-relevant-case with found IOCs and entities.

Step 7: Document & Report

Use /document-in-case (if HUNTCASEID provided).

Use /generate-report with REPORTTYPE="apthunt":

  • Hunt objective and hypothesis
  • Threat actor summary
  • TTPs investigated
  • IOCs searched
  • SIEM queries used
  • Findings (positive AND negative)
  • Recommendations

Step 8: Escalate or Conclude

Confirmed threat found: → Escalate to Incident Response → Create incident case

No threat found: → Document negative findings → Conclude hunt

Required Outputs

After completing this skill, you MUST report these outputs:

Output Description
ACTOR_IOCS IOCs associated with threat actor from GTI
ACTOR_TTPS TTPs from threat actor profile (MITRE techniques)
HUNT_RESULTS SIEM search results for actor indicators
DISCOVERED_INDICATORS IOCs found in environment matching actor profile
CONFIRMED_IOCS IOCs confirmed malicious via GTI enrichment

Key Intelligence Sources

Source Tool
Actor Profile getcollectionreport
TTPs getcollectionmitre_tree
Timeline getcollectiontimeline_events
Related IOCs getentitiesrelatedtoa_collection
Technique Details getthreatintel

Critical Requirements

  • Document ALL queries used (for reproducibility)
  • Report negative findings (no hits is valuable intel)
  • Don't report false positives as confirmed threats