What problem does it solve? Preparing for the OffSec TH-200 (OSTH) threat hunting certification requires mastering proactive detection across Splunk, CrowdStrike Falcon, and Suricata, plus writing a professional hunt report worth 70 of 70 exam points. This Skill consolidates hunting methodologies, copy-paste queries, and a report template into one structured reference. ## Core Features & Use Cases - Query Libraries: Ready-to-use SPL queries for initial access, persistence, lateral movement, C2 beaconing, and exfiltration detection, plus CrowdStrike CQL queries for process and network hunting. - Hunting Frameworks: PEAK and SEARCH methodologies, hypothesis development guidance, MITRE ATT&CK mapping, and ransomware/APT case studies (LockBit, APT29, Lazarus). - Exam Report Template: A structured hunt narrative template with timeline, IOC table, ATT&CK mapping, and chain of custody sections. - Use Case: During an 8-hour OSTH exam simulation, load the Splunk hunting reference to run beaconing detection queries, correlate findings with CrowdStrike process trees, then fill the report template with timestamped evidence. ## Quick Start Ask the agent to help you hunt for C2 beaconing activity in proxy logs using Splunk SPL and map the findings to MITRE ATT&CK techniques.