Torna agli aggiornamenti
New releaseAug 20, 2026

agentic-threat-hunting-framework v0.19.0

ATHF è un framework per la caccia alle minacce agentica - costruire sistemi che possono ricordare, apprendere e agire con autonomia crescente.

Condividi

Agentic Threat Hunting Framework (ATHF)

ATHF Logo

PyPI version PyPI downloads Python Version License: MIT GitHub stars

Avvio rapido • Installazione • Documentazione • Esempi

Date al vostro programma di threat hunting memoria e capacità di azione.

L'Agentic Threat Hunting Framework (ATHF) è il livello di memoria e automazione per il vostro programma di threat hunting. Dà alle vostre cacce struttura, persistenza e contesto - rendendo ogni indagine passata accessibile sia agli esseri umani che all'IA.

ATHF funziona con qualsiasi metodologia di hunting (PEAK, TaHiTI o il vostro processo). Non è un sostituto; è il livello che rende il vostro processo esistente pronto per l'IA.

Cos'è ATHF?

ATHF fornisce struttura e persistenza per i programmi di threat hunting. È un framework basato su markdown che:

  • Documenta le cacce usando il pattern LOCK (Learn → Observe → Check → Keep)
  • Mantiene un repository ricercabile delle indagini passate
  • Consente agli assistenti IA di fare riferimento al vostro ambiente e al lavoro precedente
  • Funziona con qualsiasi piattaforma SIEM/EDR
  • NOVITÀ: Include agenti di ricerca e generazione di ipotesi basati sull'IA (v0.3.0+)

Il Problema

La maggior parte dei programmi di threat hunting perde un contesto prezioso una volta terminata una caccia. Le note vivono in Slack o nei ticket, le query vengono scritte una volta e dimenticate, e le lezioni apprese esistono solo nella testa degli analisti.

Anche gli strumenti IA partono da zero ogni volta, senza accesso al vostro ambiente, ai vostri dati o alle vostre cacce passate.

ATHF cambia questo dando alle vostre cacce struttura, persistenza e contesto.

Leggi di più: docs/why-athf.md

Il Pattern LOCK

Ogni threat hunt segue lo stesso ciclo di base: Learn → Observe → Check → Keep.

The LOCK Pattern

  • Learn: Raccogliere contesto da threat intel, avvisi o anomalie
  • Observe: Formulare un'ipotesi sul comportamento dell'avversario
  • Check: Testare le ipotesi con query mirate
  • Keep: Registrare i risultati e le lezioni apprese

Perché LOCK? È abbastanza piccolo da essere usato e abbastanza rigoroso da poter essere interpretato dagli agenti. Catturando ogni caccia in questo formato, ATHF rende possibile per gli assistenti IA richiamare il lavoro precedente e suggerire query raffinate basate sui risultati passati.

Leggi di più: docs/lock-pattern.md

I Cinque Livelli dell'Agentic Hunting

ATHF definisce un semplice modello di maturità. Ogni livello si basa sul precedente.

La maggior parte dei team vivrà ai Livelli 1–2. Tutto ciò che va oltre è maturità opzionale.

The Five Levels

LivelloCapacitàCosa Ottenete
0Ad-hocLe cacce esistono in Slack, ticket o note degli analisti
1DocumentatoRegistrazioni persistenti delle cacce usando LOCK
2RicercabileL'IA legge e richiama le vostre cacce
3GenerativoL'IA esegue query tramite strumenti MCP, conduce ricerche
4AgenticoAgenti autonomi monitorano e agiscono, generano ipotesi

Livello 1: Operativo entro un giorno Livello 2: Operativo entro una settimana Livello 3: 2-4 settimane (opzionale) Livello 4: 1-3 mesi (opzionale)

Leggi di più: docs/maturity-model.md

🚀 Avvio rapido

Opzione 1: Installazione da PyPI (Consigliata)

# Install ATHF
pip install agentic-threat-hunting-framework

# Initialize your hunt program
athf init

# NEW: Conduct research before hunting (5-skill methodology)
athf research new --topic "LSASS dumping" --technique T1003.001

# Create your first hunt (link to research)
athf hunt new --technique T1003.001 --title "LSASS Credential Dumping" --research R-0001

Opzione 2: Installazione dal Sorgente (Sviluppo)

# Clone and install from source
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
pip install -e .

# Initialize and start hunting
athf init
athf hunt new --technique T1003.001

Opzione 3: Markdown Puro (Nessuna Installazione)

# Clone the repository
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework

# Copy a template and start documenting
mkdir -p hunts
cp athf/data/templates/HUNT_LOCK.md hunts/H-0001.md

# Customize AGENTS.md with your environment
# Add your SIEM, EDR, and data sources

Scegliete il vostro assistente IA: Claude Code, GitHub Copilot o Cursor - qualsiasi strumento in grado di leggere i file del vostro repository.

Guida completa: docs/getting-started.md

🔧 Comandi CLI

ATHF include una CLI completa per gestire le vostre cacce. Ecco un riferimento rapido:

Inizializzare il Workspace

athf init                           # Interactive setup
athf init --non-interactive         # Use defaults

Ricerca e Generazione di Ipotesi (NOVITÀ nella v0.3.0)

# Conduct thorough pre-hunt research (15-20 min)
athf research new --topic "LSASS dumping" --technique T1003.001

# Quick research for urgent hunts (5 min)
athf research new --topic "Pass-the-Hash" --depth basic

# Generate AI-powered hypothesis from threat intel
athf agent run hypothesis-generator --threat-intel "APT29 targeting SaaS"

# List research and agents
athf research list
athf agent list

Creare Cacce

athf hunt new                       # Interactive mode
athf hunt new \
  --technique T1003.001 \
  --title "LSASS Dumping Detection" \
  --platform windows \
  --hunt-type baseline \
  --research R-0001                 # Link to research document
# --hunt-type: hypothesis (default) | baseline | model-assisted

Elencare e Cercare

athf hunt list                      # Show all hunts
athf hunt list --status completed   # Filter by status
athf hunt list --directory test     # Filter by environment (test/production)
athf hunt list --hunt-type baseline # Filter by hunt category
athf hunt list --output json        # JSON output
athf hunt search "kerberoasting"    # Full-text search
athf hunt search "credential" --directory production  # Search with directory filter
athf research search "credential"   # Search research docs

Validare e Statistiche

Categorie