DE/TH COMMUNITY


Agentic Threat
Hunting Framework
ATHF is the memory and automation layer for your threat hunting program. It gives your hunts structure, persistence, and context - making past hunts accessible to both humans and agents so you never start from zero again.
The GATES METHOD
A pattern to evaluate when to promote a hunt to a detection rule and the bridge between ATHF and ADEF. Each gate has a base version for quick decisioning. The advanced version asks you to prove the answer with evidence you're already gathering: a retrohunt, an adversary emulation, or a live soak. Run it as a /skill in your pipeline or commit it to your human memory.
# a hunt finding, ready to score
$ /gates --hunt H-XXXX
G Generalizable ✓ pass repeatable behavior, not one-off
A Additive ✓ pass fills a real coverage gap
T Tunable ✓ pass parent + user context bounds FPs
E Exposure-tested ✓ pass checked against known bypasses
S Sustainable ✓ pass logging reliable, upkeep fair
5/5 cleared → promote to a standing detectionAgentic Detection Engineering Framework
ADEF gives every detection a journal, every transition a timestamp, and every lifecycle stage an agent surface that current and future engineers can read. Whether your rules live in a git repo, only in your SIEM, or a library that doesn't exist yet, ADEF wraps your rules with durable memory: why the rule exists, how it evolved, and when next it needs attention.
$ adef coverage --gaps
Coverage quality · 212 detections · 94 techniques tagged
solid 41 multiple reviewed detections
fragile 38 one rule, or unreviewed inferences only
fictional 3 technique IDs not in ATT&CK
(T1059.011, T1547.019, T1003.010)
single log source 17 techniques depend entirely on wineventlog_security
$ adef coverage --navigator layer.json
# scored layer ready for MITRE Navigator: solid / fragile / fictional as three tiersTHE / FORGE / LIFECYCLE
A five-stage cycle for the life of a detection. A deliberate, named loop that replaces ad-hoc shipping with a durable record of why a detection exists, how it was characterized, and what comes next. FORGE is iterative, not linear. Every detection has a stage, and every transition leaves a timestamped trace in a journal.