업데이트로 돌아가기
New releaseJul 31, 2026

agentic-threat-hunting-framework v0.18.0

ATHF는 에이전틱 위협 헌팅을 위한 프레임워크입니다 - 기억하고, 학습하며, 점진적 자율성을 가지고 행동하는 시스템을 구축합니다.

공유

에이전틱 위협 헌팅 프레임워크 (ATHF)

ATHF Logo

PyPI version PyPI downloads Python Version License: MIT GitHub stars

빠른 시작 • 설치 • 문서 • 예제

위협 헌팅 프로그램에 기억과 자율성을 부여하세요.

에이전틱 위협 헌팅 프레임워크 (ATHF) 는 위협 헌팅 프로그램을 위한 기억 및 자동화 계층입니다. 헌팅에 구조, 지속성, 그리고 맥락을 부여하여 모든 과거 조사를 인간과 AI 모두가 접근할 수 있게 만듭니다.

ATHF는 모든 헌팅 방법론(PEAK, TaHiTI, 또는 자체 프로세스)과 함께 작동합니다. 대체물이 아니라, 기존 프로세스를 AI에 적합하게 만드는 계층입니다.

ATHF란 무엇인가?

ATHF는 위협 헌팅 프로그램에 구조와 지속성을 제공합니다. 마크다운 기반 프레임워크로 다음을 수행합니다:

  • LOCK 패턴(Learn → Observe → Check → Keep)을 사용하여 헌팅을 문서화
  • 과거 조사에 대한 검색 가능한 저장소 유지
  • AI 어시스턴트가 귀하의 환경과 이전 작업을 참조할 수 있도록 지원
  • 모든 SIEM/EDR 플랫폼과 호환
  • 신규: AI 기반 리서치 및 가설 생성 에이전트 포함 (v0.3.0+)

문제점

대부분의 위협 헌팅 프로그램은 헌팅이 끝나면 귀중한 맥락을 잃습니다. 노트는 Slack이나 티켓에 흩어져 있고, 쿼리는 한 번 작성되고 잊히며, 교훈은 분석가의 머릿속에만 존재합니다.

AI 도구조차 귀하의 환경, 데이터, 과거 헌팅에 대한 접근 없이는 매번 처음부터 시작합니다.

ATHF는 헌팅에 구조, 지속성, 맥락을 부여함으로써 이를 바꿉니다.

더 읽기: docs/why-athf.md

LOCK 패턴

모든 위협 헌팅은 동일한 기본 루프를 따릅니다: Learn → Observe → Check → Keep.

The LOCK Pattern

  • Learn: 위협 인텔, 경보, 또는 이상 징후로부터 맥락 수집
  • Observe: 공격자 행위에 대한 가설 수립
  • Check: 표적화된 쿼리로 가설 검증
  • Keep: 발견 사항과 교훈 기록

왜 LOCK인가? 사용하기에 충분히 작고, 에이전트가 해석하기에 충분히 엄격합니다. 모든 헌팅을 이 형식으로 기록함으로써 ATHF는 AI 어시스턴트가 이전 작업을 회상하고 과거 결과를 기반으로 개선된 쿼리를 제안할 수 있게 합니다.

더 읽기: docs/lock-pattern.md

에이전틱 헌팅의 다섯 단계

ATHF는 간단한 성숙도 모델을 정의합니다. 각 단계는 이전 단계를 기반으로 구축됩니다.

대부분의 팀은 레벨 1–2에 머무릅니다. 그 이상은 모두 선택적 성숙도입니다.

The Five Levels

레벨역량얻는 것
0임시적헌팅이 Slack, 티켓, 또는 분석가 노트에 존재
1문서화됨LOCK을 사용한 지속적 헌팅 기록
2검색 가능AI가 헌팅을 읽고 회상
3생성적AI가 MCP 도구를 통해 쿼리 실행, 리서치 수행
4에이전틱자율 에이전트가 모니터링 및 행동, 가설 생성

레벨 1: 하루 안에 운영 가능 레벨 2: 일주일 안에 운영 가능 레벨 3: 2-4주 (선택적) 레벨 4: 1-3개월 (선택적)

더 읽기: docs/maturity-model.md

🚀 빠른 시작

옵션 1: PyPI에서 설치 (권장)

# Install ATHF
pip install agentic-threat-hunting-framework

# Initialize your hunt program
athf init

# NEW: Conduct research before hunting (5-skill methodology)
athf research new --topic "LSASS dumping" --technique T1003.001

# Create your first hunt (link to research)
athf hunt new --technique T1003.001 --title "LSASS Credential Dumping" --research R-0001

옵션 2: 소스에서 설치 (개발)

# Clone and install from source
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
pip install -e .

# Initialize and start hunting
athf init
athf hunt new --technique T1003.001

옵션 3: 순수 마크다운 (설치 불필요)

# Clone the repository
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework

# Copy a template and start documenting
mkdir -p hunts
cp athf/data/templates/HUNT_LOCK.md hunts/H-0001.md

# Customize AGENTS.md with your environment
# Add your SIEM, EDR, and data sources

AI 어시스턴트 선택: Claude Code, GitHub Copilot, 또는 Cursor - 저장소 파일을 읽을 수 있는 모든 도구.

전체 가이드: docs/getting-started.md

🔧 CLI 명령어

ATHF는 헌팅 관리를 위한 완전한 기능의 CLI를 포함합니다. 다음은 빠른 참조입니다:

워크스페이스 초기화

athf init                           # Interactive setup
athf init --non-interactive         # Use defaults

리서치 및 가설 생성 (v0.3.0 신규)

# Conduct thorough pre-hunt research (15-20 min)
athf research new --topic "LSASS dumping" --technique T1003.001

# Quick research for urgent hunts (5 min)
athf research new --topic "Pass-the-Hash" --depth basic

# Generate AI-powered hypothesis from threat intel
athf agent run hypothesis-generator --threat-intel "APT29 targeting SaaS"

# List research and agents
athf research list
athf agent list

헌팅 생성

athf hunt new                       # Interactive mode
athf hunt new \
  --technique T1003.001 \
  --title "LSASS Dumping Detection" \
  --platform windows \
  --hunt-type baseline \
  --research R-0001                 # Link to research document
# --hunt-type: hypothesis (default) | baseline | model-assisted

목록 및 검색

athf hunt list                      # Show all hunts
athf hunt list --status completed   # Filter by status
athf hunt list --directory test     # Filter by environment (test/production)
athf hunt list --hunt-type baseline # Filter by hunt category
athf hunt list --output json        # JSON output
athf hunt search "kerberoasting"    # Full-text search
athf hunt search "credential" --directory production  # Search with directory filter
athf research search "credential"   # Search research docs

검증 및 통계

athf hunt validate                  # Validate all hunts
athf hunt validate H-0001           # Validate specific hunt
athf hunt stats                     # Show statistics (incl. hunts by type)
athf hunt stats --by hunt_type --status completed --output json  # Category breakdown
athf hunt coverage                  # MITRE ATT&CK coverage
athf research stats                 # Research metrics

ATT&CK 데이터 관리 (v0.11.0 신규)

# Install STIX support (optional)
pip install 'agentic-threat-hunting-framework[attack]'

# Download live ATT&CK data (835+ techniques with full metadata)
athf attack update

# Check provider status
athf attack status

# Look up technique metadata
athf attack lookup T1003.001

# List techniques for a tactic
athf attack techniques credential-access

mitreattack-python 없이 ATHF는 하드코딩된 v14 폴백(14개 전술, 대략적인 개수)을 사용합니다. 이를 설치하면 전체 기법 메타데이터(플랫폼, 데이터 소스, 하위 기법, 정확한 개수)를 얻을 수 있습니다.

MCP 서버 (v0.11.0 신규)

# Install MCP dependencies
pip install 'agentic-threat-hunting-framework[mcp]'

# Start MCP server (for Claude Code, Copilot, Cursor, etc.)
athf mcp serve --workspace /path/to/hunts

~/.claude/mcp-servers.json에서 구성:

{
  "athf": {
    "command": "athf-mcp",
    "env": { "ATHF_WORKSPACE": "/path/to/your/hunts" }
  }
}

독립 실행형 athf-mcp 진입점은 cwd 또는 ATHF_WORKSPACE 환경 변수에서 워크스페이스를 자동 감지합니다. 명시적 경로에는 athf mcp serve --workspace /path를 사용하세요.

보안 참고: sse 및 streamable-http 전송은 127.0.0.1에 바인딩되며 인증되지 않습니다. 모든 도구는 전체 워크스페이스를 읽고 일부는 귀하의 비용으로 LLM 에이전트를 호출합니다. 라우팅 가능한 인터페이스에 바인딩하려면 --host를 전달하고, 그럴 때는 인증 프록시를 앞에 두세요. 기본 stdio 전송은 소켓을 전혀 열지 않습니다.

17개 도구를 노출합니다: 헌팅 관리, 시맨틱 검색, ATT&CK 커버리지, 리서치, 조사, 그리고 AI 기반 가설 생성 — 모두 AI 코딩 어시스턴트에서 직접 접근 가능합니다.

전체 문서: CLI Reference

📺 실제 작동 모습

카테고리