
What this means
Open source AI agents vetted for production. Exchange Inspector combines frontier assessment using OpenAI GPT cyber models, skills inspection powered by Tenable One AI Exposure, and expert review from Tenable researchers.
AI component inspection is powered by Tenable One AI Exposure — the same skills inspection technology that can secure the agents already running across your enterprise.
SOC-Hunter
Proactive, hypothesis-driven threat hunting using the LOCK pattern across SIEM, EDR, VM, CSPM, CASB, and code search
Vetted at the commit linked above. The review covers that commit only, not later changes to the repository. Learn more about our security review process.
SOC Hunter Builder Interview
Get your own builder interview.Book a spot →
CyberAgents Exchange AI Inspector Vetted
SOC-Hunter was inspected with Tenable One AI Exposure
The same skills inspection technology that vetted this listing can secure the agents already running across your enterprise.
Request a Demo →SOC-Hunter is a Claude Code skill that brings structured, proactive threat hunting to your IR workstation. Instead of waiting for alerts, you form hypotheses and systematically test them across your entire security data stack using the LOCK pattern (Learn, Observe, Check, Keep).
What it does
- Runs seven hunting modes:
hunt,research,execute,review,baseline,investigate, andlookup - Orchestrates queries across SIEM, EDR, Vulnerability Management, CSPM, CASB, Log Analytics, IPAM, and Code Search via MCP — in a structured layered correlation approach
- Maps every hunt to MITRE ATT&CK with live STIX coverage analysis and gap detection
- Maintains persistent hunt memory across sessions (
hunts/,research/,investigations/) - Detects statistical deviations from versioned behavioral baselines (sigma scoring)
- Fully vendor-agnostic — configure your own MCP servers, SIEM indexes, and credentials via
CONFIG.md
How it works
Each hunt follows four approval-gated phases: Learn (hypothesis + ABLE scoping), Observe (define normal vs. suspicious, map to data sources), Check (count-first query execution across 7 data source layers), and Keep (structured hunt file with TP/FP classification and lessons learned). Lightweight investigations use the TRACE pattern (Trigger, Recon, Assess, Conclude, Emit) for quick structured triage without full LOCK overhead. Built-in quality tools — hunt-similar.py, hunt-validate.py, and attack-lookup.py — prevent duplicate work and enforce frontmatter consistency across the hunt library.
