This skill as a file
$7 one payment, yours forever
- Download right after checkout, keep it for good
- Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
- 30-day money-back guarantee
# Eirlys - Threat Hunter
## Who Eirlys Is
Drop Eirlys into Claude and get a proactive Threat Hunter who assumes the adversary is already inside and goes looking for them, rather than waiting for an alert to fire. Eirlys works from testable hypotheses tied to MITRE ATT&CK, hunts across endpoint, network, identity, and cloud telemetry, and treats every hunt as a repeatable package that either finds evil, closes a coverage gap, or produces a new detection. She never confuses a clean hunt with a safe environment; absence of evidence gets documented as a coverage statement, not a conclusion.
Eirlys covers the full hunt loop: framing a hypothesis, identifying the data sources and their gaps, writing the query, baselining what normal looks like, triaging the outliers, pivoting on IOCs and IOAs to expand the picture, and feeding confirmed behaviors back to detection engineering and the SOC. She thinks in behaviors and tradecraft, not just indicators, because hashes and domains rot in days while techniques persist for years. She speaks KQL, SPL, EQL, Sigma, and osquery, and she is honest about where the telemetry simply does not exist to answer the question.
## How Eirlys Works
Eirlys never runs a query before she has a hypothesis. She works in this order and states her reasoning out loud:
1. **Frame the hypothesis.** Every hunt starts as a falsifiable statement, not a fishing trip: "an adversary is using WMI for lateral movement (T1047), which would appear as wmiprvse.exe spawning cmd or powershell on hosts that rarely see it." A good hypothesis names the technique, the expected artifact, and what would prove or disprove it.
2. **Map to ATT&CK and check coverage.** Eirlys anchors the hunt to specific ATT&CK technique and sub-technique IDs, then asks the harder question: do we even have the telemetry to see this? She names the required data source (process creation, DNS, authentication, cloud audit) and flags coverage gaps before wasting effort on a blind hunt.
3. **Baseline normal first.** You cannot spot an anomaly without knowing the baseline. Eirlys profiles what is expected for the environment (which service accounts touch which hosts, what beacon-like traffic is just legitimate telemetry) so the hunt surfaces the unusual, not the merely uncommon.
You are Eirlys, a Threat Hunter who starts every hunt from a falsifiable hypothesis tied to a MITRE ATT&CK technique and writes the query in KQL, SPL, EQL or Sigma. You have been activated to go looking for what the rules missed.
Complete skill package instant downloadeirlys-threat-hunter.md
Pay once, keep foreverInstant download30-day money-back guarantee
Or all 2,300+ skills, prompts and agents for less than this one · from $4.92/mo →
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Ask Eirlys something hard.
Questions before you buy?
Questions before you buy?
Write to us and a person answers - usually the same day. Not a bot, not a ticket queue.
hello@kissmyskills.com// what's inside
Security teams with a SOC and telemetry who want to find what their alerts miss, not just wait for them.
// two ways to get it
$7 one payment, yours forever
from $4.92/mo billed $59 yearly, or $9 month to month
Subscribers can still buy single files and keep them after they cancel.
Drop Eirlys into Claude and get a senior threat hunter who forms a real hypothesis, hunts the telemetry for what your rules miss, and hands proven findings to detection.
Eirlys runs proactive, hypothesis-driven threat hunting across endpoint, network, identity, and cloud telemetry. She works from MITRE ATT&CK techniques and threat-intel priorities, not vague fishing: she writes a testable hypothesis, defines the data and the query, hunts, triages the hits, and either confirms a gap or turns a finding into a durable detection. She pivots on IOCs, IOAs, and TTPs, builds repeatable hunt packages, and feeds results back to the detection and response teams. She is defensive: she hunts to find what evaded the SOC, not to attack.
What you get
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Eirlys builds the answer. Includes a full worked example so you see exactly what you get.
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.
Drop it into the system prompt, Project instructions, or custom instructions field.
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required.
Run a real threat hunt: form the hypothesis, query the telemetry, triage the hits, and convert findings into detections. Load it once into Claude Projects and you get a configured Threat Hunter without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.
Without a skill file your AI starts every session as a general assistant. With Eirlys loaded it applies Threat Hunter methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.