hunt

Analyze PCAP files and Suricata EVE JSON logs to detect malicious network activity.

2|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-stamusnetworks
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: hunt
Source: https://github.com/StamusNetworks/stamus-ai-tools/tree/main/plugins/suricata-analyze/skills/hunt
Command: npx skills add https://github.com/StamusNetworks/stamus-ai-tools --skill hunt-stamusnetworks

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Analyzes PCAPs and Suricata EVE JSON logs to surface hidden threats and anomalous network activity by applying threat-hunting techniques.

Core Features & Use Cases

  • Unified analysis of PCAPs and EVE JSON logs to detect suspicious patterns and security events.
  • 10+ structured hunting queries for detecting C2 activity, data exfiltration, DNS tunneling, TLS anomalies, and beaconing.
  • Container-friendly workflow with optional rules-based context integration for testing and validation.
  • Incident-ready outputs and workflow integration for investigations.

Quick Start

Analyze a provided PCAP or EVE JSON log to surface critical alerts and suspicious patterns.

Frequently Asked Questions about hunt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect malware C2 activity and DNS tunneling from PCAP files?▼

Detecting malware C2 activity and DNS tunneling from PCAP files is achieved by applying structured threat-hunting queries to surface suspicious network patterns and security events. The analysis identifies malicious traffic using Suricata EVE JSON logs and packet captures to produce investigator-ready results.

What is the best way to hunt for TLS anomalies and beaconing in Suricata EVE logs?▼

Hunting for TLS anomalies and beaconing in Suricata EVE logs is best done using jq-based queries that analyze EVE JSON output for suspicious patterns. This surfaces hidden threats and anomalous network activity by applying threat-hunting techniques to captured traffic.

Can I analyze PCAPs for data exfiltration without configuring local Suricata rules?▼

You can analyze PCAPs for data exfiltration without local Suricata rules, as the workflow supports security monitoring with or without them. Optional rules-based context integration is available for testing and validation during threat-hunting workflows.

Does the threat hunting workflow support container-friendly execution for incident investigations?▼

The threat hunting workflow supports container-friendly execution for incident investigations, analyzing PCAPs and Suricata EVE JSON logs to surface hidden threats. It delivers incident-ready outputs and workflow integration for security monitoring.