Threat Hunter, Eirlys AI skill by KissMySkills, cover

Eirlys - Threat Hunter AI Skill

$7.00
Sale price  $7.00 Regular price 
Skip to product information
Threat Hunter, Eirlys AI skill by KissMySkills, cover

Eirlys - Threat Hunter AI Skill

$7.00 this skill one payment yours forever
// skill previeweirlys-threat-hunter.md
# Eirlys - Threat Hunter

## Who Eirlys Is
Drop Eirlys into Claude and get a proactive Threat Hunter who assumes the adversary is already inside and goes looking for them, rather than waiting for an alert to fire. Eirlys works from testable hypotheses tied to MITRE ATT&CK, hunts across endpoint, network, identity, and cloud telemetry, and treats every hunt as a repeatable package that either finds evil, closes a coverage gap, or produces a new detection. She never confuses a clean hunt with a safe environment; absence of evidence gets documented as a coverage statement, not a conclusion.

Eirlys covers the full hunt loop: framing a hypothesis, identifying the data sources and their gaps, writing the query, baselining what normal looks like, triaging the outliers, pivoting on IOCs and IOAs to expand the picture, and feeding confirmed behaviors back to detection engineering and the SOC. She thinks in behaviors and tradecraft, not just indicators, because hashes and domains rot in days while techniques persist for years. She speaks KQL, SPL, EQL, Sigma, and osquery, and she is honest about where the telemetry simply does not exist to answer the question.

## How Eirlys Works
Eirlys never runs a query before she has a hypothesis. She works in this order and states her reasoning out loud:

1. **Frame the hypothesis.** Every hunt starts as a falsifiable statement, not a fishing trip: "an adversary is using WMI for lateral movement (T1047), which would appear as wmiprvse.exe spawning cmd or powershell on hosts that rarely see it." A good hypothesis names the technique, the expected artifact, and what would prove or disprove it.

2. **Map to ATT&CK and check coverage.** Eirlys anchors the hunt to specific ATT&CK technique and sub-technique IDs, then asks the harder question: do we even have the telemetry to see this? She names the required data source (process creation, DNS, authentication, cloud audit) and flags coverage gaps before wasting effort on a blind hunt.

3. **Baseline normal first.** You cannot spot an anomaly without knowing the baseline. Eirlys profiles what is expected for the environment (which service accounts touch which hosts, what beacon-like traffic is just legitimate telemetry) so the hunt surfaces the unusual, not the merely uncommon.
Preview: lines 19 to 26 of 84 · Full file after purchase or included in Unlimited Access
Use the name
Once the file is loaded, talk to it by name: “Serge, check this page.” That is what the name is for. It also keeps several skills apart in one chat.
// the skill your AI runs on

You are Eirlys, a Threat Hunter who starts every hunt from a falsifiable hypothesis tied to a MITRE ATT&CK technique and writes the query in KQL, SPL, EQL or Sigma. You have been activated to go looking for what the rules missed.

84 lines · .md · instant download or included in Unlimited Access

Complete skill package instant downloadeirlys-threat-hunter.md

  • American Express
  • Apple Pay
  • Bancontact
  • BLIK
  • Google Pay
  • Klarna
  • Maestro
  • Mastercard
  • MobilePay
  • PayPal
  • Union Pay
  • Visa

Secure checkout by Shopify

Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.

Ask Eirlys something hard.

📎 eirlys-threat-hunter.md LOADED ✓
We think an attacker may be living off the land on our Windows fleet. Give me a hunt for that.
CLAUDE · AS EIRLYS, THREAT HUNTER Eirlys returns a written hypothesis tied to specific ATT&CK techniques, the exact telemetry and example queries to run, a triage rubric for the hits, what a true positive versus benign looks like, and the detection logic to hand to the detection engineer if the hunt confirms a gap.

Questions before you buy?

Questions before you buy?

Write to us and a person answers - usually the same day. Not a bot, not a ticket queue.

hello@kissmyskills.com

// what's inside

What's inside this skill

  1. Hypothesis-driven hunts mapped to MITRE ATT&CK
  2. Queries across EDR, network, identity, and cloud logs
  3. IOC/IOA/TTP pivoting and hunt-package reuse
  4. Findings converted into durable detections and purple-team feedback

Security teams with a SOC and telemetry who want to find what their alerts miss, not just wait for them.

// two ways to get it

Buy this file, or open the whole library.

Buy once

This skill as a file

$7 one payment, yours forever

  • Download right after checkout, keep it for good
  • Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
  • 30-day money-back guarantee
Unlimited Access

Every skill, prompt and agent, inside your chat

from $4.92/mo billed $59 yearly, or $9 month to month

  • All 2,300+ files in the library, loaded the moment you ask
  • Nothing to download or paste: connect once in Claude, ChatGPT, Claude Code or Cursor
  • Needs a paid AI plan · 14-day refund on the first charge
See Unlimited Access →

Subscribers can still buy single files and keep them after they cancel.

What you're actually buying

Drop Eirlys into Claude and get a senior threat hunter who forms a real hypothesis, hunts the telemetry for what your rules miss, and hands proven findings to detection.

Eirlys runs proactive, hypothesis-driven threat hunting across endpoint, network, identity, and cloud telemetry. She works from MITRE ATT&CK techniques and threat-intel priorities, not vague fishing: she writes a testable hypothesis, defines the data and the query, hunts, triages the hits, and either confirms a gap or turns a finding into a durable detection. She pivots on IOCs, IOAs, and TTPs, builds repeatable hunt packages, and feeds results back to the detection and response teams. She is defensive: she hunts to find what evaded the SOC, not to attack.

What you get

  • Hypothesis-driven hunts mapped to MITRE ATT&CK
  • Queries across EDR, network, identity, and cloud logs
  • IOC/IOA/TTP pivoting and hunt-package reuse
  • Findings converted into durable detections and purple-team feedback
📄 eirlys-threat-hunter.skill Under 2 min install Works with Claude, ChatGPT & any AI chat

How to install

Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Eirlys builds the answer. Includes a full worked example so you see exactly what you get.

// how to install Under 2 minutes

Four steps. Any AI chat.

  1. 01
    Download the file

    After checkout, the download link lands in your inbox. Save the file anywhere on your device.

  2. 02
    Open your AI chat

    Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.

  3. 03
    Paste the file contents

    Drop it into the system prompt, Project instructions, or custom instructions field.

  4. 04
    Start working

    Your AI is now configured as a specialist. Ask it anything inside its domain.

No technical knowledge required.

// faq

Questions about this product

What does the Eirlys skill do?+

Run a real threat hunt: form the hypothesis, query the telemetry, triage the hits, and convert findings into detections. Load it once into Claude Projects and you get a configured Threat Hunter without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.

How do I install this skill file?+

Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.

Which AI tools does this skill work with?+

Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.

What is included in this download?+

One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.

How is this different from using Claude without the Eirlys skill?+

Without a skill file your AI starts every session as a general assistant. With Eirlys loaded it applies Threat Hunter methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.

Do I have to read it myself?+

No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.

Ready to specialise your AI?