DE/TH
COMMUNITY

Agentic Threat

Hunting Framework

ATHF is the memory and automation layer for your threat hunting program. It gives your hunts structure, persistence, and context - making past hunts accessible to both humans and agents so you never start from zero again.

THE / LOCK / PATTERN
Most hunting programs stall because every analyst starts each hunt differently. Humans improvise and AI improvises, and that’s when context breaks.LOCK gives your team a single loop to follow. It keeps humans and AI aligned. It reduces repeated work. It turns every hunt into a repeatable process instead of a one-off effort.
Learn Observe Check Keep
A Quick Look at the CLI Workflow
── 1. Initialize your workspace ──
$ git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
$ cd agentic-threat-hunting-framework
$ pip install -e .
Obtaining file:///path/to/agentic-threat-hunting-framework
Installing collected packages: athf
Successfully installed athf-0.1.0
$ athf init
✓ Created workspace configuration: .athfconfig.yaml
✓ Initialized directories:
• hunts/
• templates/
• knowledge/
• queries/
✓ Context files ready: AGENTS.md, environment.md
This command builds the full workspace: hunts, templates, knowledge files, and context files. It gives your program a consistent memory layer.
── 2. Create a new hunt ──
$ athf hunt new --technique T1005 --title "macOS Data Collection Review"
✓ Created hunt: H-0001
Hunt Details:
ID: H-0001
Title: macOS Data Collection Review
Technique: T1005 - Data from Local System
Status: in-progress
File: hunts/H-0001.md
The CLI generates a LOCK-ready hunt file with every required section in place.
── 3. Validate your hunts ──
$ athf hunt validate
Validating hunt structure...
✓ H-0001.md
✓ YAML frontmatter valid
✓ LOCK sections present (Learn, Observe, Check, Keep)
✓ Required metadata found
All hunts validated successfully!
Validation ensures structure stays consistent across hunts. AI tools rely on this consistency once they start reading and reasoning over your repository.
── 4. Track ATT&CK coverage ──
$ athf hunt coverage
MITRE ATT&CK Coverage Report
────────────────────────────────────────
Collection (TA0009)
✓ T1005 - Data from Local System (1 hunt)
Coverage Summary:
Total Techniques: 1
Tactics Covered: 1
Hunt Count: 1
Suggested next hunts:
• T1003 - OS Credential Dumping
• T1059 - Command and Scripting Interpreter
• T1560 - Archive Collected Data
This command shows which techniques you cover and where gaps remain. It removes the need to maintain your own spreadsheets.
── 5. Use AI assistants with your repo ──
Open your repo in an AI coding assistant
You ask: "What should I hunt for next based on H-0001?"
AI reads:
• hunts/H-0001.md (your hunt context)
• AGENTS.md (your environment)
• knowledge/hunting-knowledge.md (expert frameworks)
AI responds:
"Based on H-0001's findings (Atomic Stealer targeting Safari/Chrome), I suggest extending to Firefox and Brave browsers. Your H-0001 query pattern (unsigned process + rapid file access) can be adapted.
Run: athf hunt new --technique T1005 --title "Firefox Data Collection""
AI assistants use your hunt memory to provide context-aware suggestions, referencing past work automatically.
Complete CLI Workflow!
You now have:
✓ Initialized workspace with full memory layer
✓ LOCK-structured hunt documentation (H-0001)
✓ Validated hunt format for AI consistency
✓ ATT&CK coverage visibility
✓ AI-readable context for intelligent assistance
Your threat hunting program now has memory and agency.
Agentic Threat Hunting Framework

The GATES METHOD

Generalizable
>
Additive
>
Tunable
>
Exposure-tested
>
Sustainable

A pattern to evaluate when to promote a hunt to a detection rule and the bridge between ATHF and ADEF. Each gate has a base version for quick decisioning. The advanced version asks you to prove the answer with evidence you're already gathering: a retrohunt, an adversary emulation, or a live soak. Run it as a /skill in your pipeline or commit it to your human memory.

READ MORE
# a hunt finding, ready to score
$ /gates --hunt H-XXXX

  G  Generalizable    ✓ pass   repeatable behavior, not one-off
  A  Additive         ✓ pass   fills a real coverage gap
  T  Tunable          ✓ pass   parent + user context bounds FPs
  E  Exposure-tested  ✓ pass   checked against known bypasses
  S  Sustainable      ✓ pass   logging reliable, upkeep fair

  5/5 cleared → promote to a standing detection

Agentic Detection 
Engineering Framework

ADEF gives every detection a journal, every transition a timestamp, and every lifecycle stage an agent surface that current and future engineers can read. Whether your rules live in a git repo, only in your SIEM, or a library that doesn't exist yet, ADEF wraps your rules with durable memory: why the rule exists, how it evolved, and when next it needs attention.

Agentic Detection Engineering Framework
  1. Find
  2. Observe
  3. Refine
  4. Govern
  5. Evolve

Detections never finish, they iterate

$ adef coverage --gaps

  Coverage quality · 212 detections · 94 techniques tagged

  solid        41   multiple reviewed detections
  fragile      38   one rule, or unreviewed inferences only
  fictional     3   technique IDs not in ATT&CK
                    (T1059.011, T1547.019, T1003.010)

  single log source   17 techniques depend entirely on wineventlog_security

$ adef coverage --navigator layer.json
# scored layer ready for MITRE Navigator: solid / fragile / fictional as three tiers

THE / FORGE / LIFECYCLE

A five-stage cycle for the life of a detection. A deliberate, named loop that replaces ad-hoc shipping with a durable record of why a detection exists, how it was characterized, and what comes next.
FORGE is iterative, not linear. Every detection has a stage, and every transition leaves a timestamped trace in a journal.

FOR MORE 

FRAMEWORKS & Skills

Visit GitHub