Works with
Threat Detection
Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, z-score anomaly detection, and MITRE ATT&CK-mapped signal prioritization.
Optimized workflow
This edition turns the source methodology into a repeatable agent workflow with explicit inputs, checkpoints and deliverables.
Quality standard
- Confirm scope and missing inputs before execution
- Ground decisions in available evidence and preserve source constraints
- Return an actionable result with assumptions, risks and next steps
Agent compatibility
The same core method is packaged for Claude, Codex, GPT, Gemini, Cursor and OpenCode.
Permissions & security
Source verified · conversion tested · security signals reviewed