ti_hunt_package
Generate a complete hunt package from industry, region, and scenario: threat actors, priority TTPs, detection coverage analysis, gaps, and vendor intelligence, ready for use-case tracker import.
Instructions
ELITE: THE ULTIMATE HUNT TOOL. Given a client context (industry + region + scenario), produce a complete hunt package: relevant threat actors, priority TTPs, detection coverage analysis, coverage gaps, and vendor intelligence — all fused from multi-source data. Output is structured for direct import into a use-case tracker.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| region | Yes | Client region (e.g., Middle East, UK, US) | |
| industry | Yes | Client industry (e.g., healthcare, finance, energy) | |
| scenario | Yes | Threat scenario (e.g., ransomware, espionage, supply-chain) | |
| log_sources | No | Available log sources (e.g., ["sysmon", "crowdstrike", "azure_ad"]) | |
| max_techniques | No | Max techniques to analyze (default: 15) |