What problem does it solve? Security teams often run ad-hoc hunts that lack rigor: vague hypotheses, unscored priorities, missing source citations, and no path from a validated hunt to a production detection. This Skill enforces a disciplined hypothesis lifecycle so hunts are specific, testable, traceable to intelligence, and convertible into deployable detections. ## Core Features & Use Cases - ABLE Hypothesis Framework: Structures every hunt around Actor, Behaviour, Location, and Evidence, with completeness checks and data-gap registration when telemetry is missing. - Scoring & Prioritization: Scores confidence, relevance, priority, and effort with defined criteria, plus anti-pattern checks (tautology, kitchen-sink, orphan, technology hunt, time traveler). - Hunt-to-Detection Bridge: Converts validated hunts into OpenTide TVM/DOM/MDR objects via a 7-step conversion process, and feeds blind spots back into data requirements. - Use Case: Given a CTI report describing an actor's lateral movement TTP, generate an ABLE-complete hypothesis with verbatim source quotes, map evidence to EDR and SIEM telemetry, score it, execute per-platform queries, classify results, and convert a confirmed hunt into a production detection rule. ## Quick Start Use the threat-hunting skill to turn this threat intelligence report into a scored, ABLE-complete hunt hypothesis with evidence mapping and a verdict workflow.