Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
thrunt-god — Threat hunting command system for agentic IDEs | Kitploit
Tools/GitHubGitHub/backbay-labs/thrunt-god
Indicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)ReconnaissanceScripting & AutomationInformation GatheringThreat IntelligenceIntrusion DetectionIncident Response
GitHubbackbay-labs/thrunt-god

thrunt-god

Threat hunting command system for agentic IDEs

View Repository
368712 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

THRUNT GOD

npm CI Status Discord License: MIT

From signal, to swarm.
No gods. Only Thrunt.

Threat hunting command system for agentic IDEs.
Claude Code · OpenCode · Gemini · Codex · Copilot · Cursor · Windsurf

/thrunt:autonomous  |  one command, full hunt

Install  ·   Phases  ·   Commands  ·   Flows  ·   Artifacts


Installation

npx thrunt-god@latest --claude --local

thrunt-god install

Bootstrap the hunt command surface into your local IDE environment.

IDECommand
Claude Code / Gemini/hunt:help
OpenCode/hunt-help
Codex$hunt-help
Copilot/hunt-help
Cursor / Windsurfhunt-help

Install the VS Code extension alpha

Download thrunt-god-0.3.0.vsix from the v0.3.0 release.

Then install it one of two ways:

  1. In VS Code, open Extensions, click the ... menu, choose Install from VSIX..., and select the downloaded file.
  2. From terminal:
code --install-extension thrunt-god-0.3.0.vsix

After install, open a folder containing .planning/MISSION.md or .hunt/MISSION.md and the THRUNT sidebar will activate automatically.


The Five Phases

Every hunt resolves through five phases. Each step is explicit.

Signal → Hunt → Swarm → Receipt → Publish

Phase
SignalA detection, anomaly, lead, or intel input opens the case
HuntHypotheses are formed, scoped, and made testable
SwarmParallel agents execute structured investigations across available sources
ReceiptEvery claim is bound to exact queries, timestamps, and evidence lineage
PublishOnly validated findings are packaged for downstream consumers

Hunt Commands

CommandPurpose
/hunt:new-programStand up a long-lived hunt program
/hunt:new-caseOpen a case from a signal
/hunt:map-environmentInventory data sources, access, and topology
/hunt:shape-hypothesisDevelop and refine testable hypotheses
/hunt:plan <phase>Plan a hunt phase
/hunt:run <phase>Execute a hunt phase
/hunt:validate-findings [phase]Validate evidence chain for findings
/hunt:publish [target]Package and ship findings
/hunt:helpShow all commands and usage

Thrunt Commands

Utility and orchestration commands (/thrunt:*) for workspace management, diagnostics, settings, and agent control.


Common Flows

Single signal

/hunt:new-case
/hunt:shape-hypothesis
/hunt:plan 1
/hunt:run 1
/hunt:validate-findings 1
/hunt:publish

Long-lived program

/hunt:new-program
/hunt:map-environment
/hunt:new-case
  ... repeat per signal ...

Pack-seeded signal

/hunt:new-case --pack domain.identity-abuse
/hunt:run 1
/hunt:validate-findings 1

Autonomous

/thrunt:autonomous

Runs all remaining phases end-to-end: discuss, plan, execute. Pauses only for operator decisions.


Artifacts

All hunt state lives in a planning directory at the project root (.planning/ by default). Every query, receipt, and finding is a file, not a summary.

.planning/
├── config.json             # Project settings (mode, profile, connectors, workflow toggles)
├── MISSION.md              # Hunt program mission and scope
├── HYPOTHESES.md           # Testable hypotheses with status tracking
├── SUCCESS_CRITERIA.md     # Definition of done for the program
├── HUNTMAP.md              # Phase breakdown and execution roadmap
├── STATE.md                # Current phase, progress, blockers
├── FINDINGS.md             # Validated findings only
├── EVIDENCE_REVIEW.md      # Evidence chain audit
├── QUERIES/                # Exact queries run, with timestamps
├── RECEIPTS/               # Execution receipts per phase task
├── DETECTIONS/             # Detection rules promoted from findings
├── environment/
│   └── ENVIRONMENT.md      # Data source inventory and access map
├── phases/                 # Per-phase plans, research, and results
├── workstreams/            # Parallel hunt cases (optional)
├── milestones/             # Archived completed milestones
└── published/              # Final deliverables

Configuration

Settings live in .planning/config.json, created by /hunt:new-program and editable via /thrunt:settings. Global defaults in ~/.thrunt/defaults.json are merged into every new project config.

SettingDefaultWhat it controls
modeinteractiveinteractive confirms at each step, yolo auto-approves
granularitystandardPhase count: coarse (3-5), standard (5-8), fine (8-12)
model_profilebalancedModel tier per agent: quality, balanced, budget, inherit
planning.commit_docstrueWhether .planning/ is committed to git
git.branching_strategynonenone, phase (branch per phase), milestone (branch per version)
Download Tool