
agentic-threat-hunting-framework v0.19.0
ATHF è un framework per la caccia alle minacce agentica - costruire sistemi che possono ricordare, apprendere e agire con autonomia crescente.
Agentic Threat Hunting Framework (ATHF)

Avvio rapido • Installazione • Documentazione • Esempi
Date al vostro programma di threat hunting memoria e capacità di azione.
L'Agentic Threat Hunting Framework (ATHF) è il livello di memoria e automazione per il vostro programma di threat hunting. Dà alle vostre cacce struttura, persistenza e contesto - rendendo ogni indagine passata accessibile sia agli esseri umani che all'IA.
ATHF funziona con qualsiasi metodologia di hunting (PEAK, TaHiTI o il vostro processo). Non è un sostituto; è il livello che rende il vostro processo esistente pronto per l'IA.
Cos'è ATHF?
ATHF fornisce struttura e persistenza per i programmi di threat hunting. È un framework basato su markdown che:
- Documenta le cacce usando il pattern LOCK (Learn → Observe → Check → Keep)
- Mantiene un repository ricercabile delle indagini passate
- Consente agli assistenti IA di fare riferimento al vostro ambiente e al lavoro precedente
- Funziona con qualsiasi piattaforma SIEM/EDR
- NOVITÀ: Include agenti di ricerca e generazione di ipotesi basati sull'IA (v0.3.0+)
Il Problema
La maggior parte dei programmi di threat hunting perde un contesto prezioso una volta terminata una caccia. Le note vivono in Slack o nei ticket, le query vengono scritte una volta e dimenticate, e le lezioni apprese esistono solo nella testa degli analisti.
Anche gli strumenti IA partono da zero ogni volta, senza accesso al vostro ambiente, ai vostri dati o alle vostre cacce passate.
ATHF cambia questo dando alle vostre cacce struttura, persistenza e contesto.
Leggi di più: docs/why-athf.md
Il Pattern LOCK
Ogni threat hunt segue lo stesso ciclo di base: Learn → Observe → Check → Keep.

- Learn: Raccogliere contesto da threat intel, avvisi o anomalie
- Observe: Formulare un'ipotesi sul comportamento dell'avversario
- Check: Testare le ipotesi con query mirate
- Keep: Registrare i risultati e le lezioni apprese
Perché LOCK? È abbastanza piccolo da essere usato e abbastanza rigoroso da poter essere interpretato dagli agenti. Catturando ogni caccia in questo formato, ATHF rende possibile per gli assistenti IA richiamare il lavoro precedente e suggerire query raffinate basate sui risultati passati.
Leggi di più: docs/lock-pattern.md
I Cinque Livelli dell'Agentic Hunting
ATHF definisce un semplice modello di maturità. Ogni livello si basa sul precedente.
La maggior parte dei team vivrà ai Livelli 1–2. Tutto ciò che va oltre è maturità opzionale.

| Livello | Capacità | Cosa Ottenete |
|---|---|---|
| 0 | Ad-hoc | Le cacce esistono in Slack, ticket o note degli analisti |
| 1 | Documentato | Registrazioni persistenti delle cacce usando LOCK |
| 2 | Ricercabile | L'IA legge e richiama le vostre cacce |
| 3 | Generativo | L'IA esegue query tramite strumenti MCP, conduce ricerche |
| 4 | Agentico | Agenti autonomi monitorano e agiscono, generano ipotesi |
Livello 1: Operativo entro un giorno Livello 2: Operativo entro una settimana Livello 3: 2-4 settimane (opzionale) Livello 4: 1-3 mesi (opzionale)
Leggi di più: docs/maturity-model.md
🚀 Avvio rapido
Opzione 1: Installazione da PyPI (Consigliata)
# Install ATHF
pip install agentic-threat-hunting-framework
# Initialize your hunt program
athf init
# NEW: Conduct research before hunting (5-skill methodology)
athf research new --topic "LSASS dumping" --technique T1003.001
# Create your first hunt (link to research)
athf hunt new --technique T1003.001 --title "LSASS Credential Dumping" --research R-0001
Opzione 2: Installazione dal Sorgente (Sviluppo)
# Clone and install from source
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
pip install -e .
# Initialize and start hunting
athf init
athf hunt new --technique T1003.001
Opzione 3: Markdown Puro (Nessuna Installazione)
# Clone the repository
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
# Copy a template and start documenting
mkdir -p hunts
cp athf/data/templates/HUNT_LOCK.md hunts/H-0001.md
# Customize AGENTS.md with your environment
# Add your SIEM, EDR, and data sources
Scegliete il vostro assistente IA: Claude Code, GitHub Copilot o Cursor - qualsiasi strumento in grado di leggere i file del vostro repository.
Guida completa: docs/getting-started.md
🔧 Comandi CLI
ATHF include una CLI completa per gestire le vostre cacce. Ecco un riferimento rapido:
Inizializzare il Workspace
athf init # Interactive setup
athf init --non-interactive # Use defaults
Ricerca e Generazione di Ipotesi (NOVITÀ nella v0.3.0)
# Conduct thorough pre-hunt research (15-20 min)
athf research new --topic "LSASS dumping" --technique T1003.001
# Quick research for urgent hunts (5 min)
athf research new --topic "Pass-the-Hash" --depth basic
# Generate AI-powered hypothesis from threat intel
athf agent run hypothesis-generator --threat-intel "APT29 targeting SaaS"
# List research and agents
athf research list
athf agent list
Creare Cacce
athf hunt new # Interactive mode
athf hunt new \
--technique T1003.001 \
--title "LSASS Dumping Detection" \
--platform windows \
--hunt-type baseline \
--research R-0001 # Link to research document
# --hunt-type: hypothesis (default) | baseline | model-assisted
Elencare e Cercare
athf hunt list # Show all hunts
athf hunt list --status completed # Filter by status
athf hunt list --directory test # Filter by environment (test/production)
athf hunt list --hunt-type baseline # Filter by hunt category
athf hunt list --output json # JSON output
athf hunt search "kerberoasting" # Full-text search
athf hunt search "credential" --directory production # Search with directory filter
athf research search "credential" # Search research docs