
agentic-threat-hunting-framework v0.18.0
ATHF是一个用于自主威胁狩猎的框架——构建能够记忆、学习并以更高自主性行动的系统。
智能体威胁狩猎框架(ATHF)

为你的威胁狩猎项目赋予记忆与自主能力。
智能体威胁狩猎框架(ATHF) 是你的威胁狩猎项目的记忆与自动化层。它为你的狩猎提供结构、持久性和上下文——让每一次过往调查都能被人类和 AI 访问。
ATHF 可与任何狩猎方法论配合使用(PEAK、TaHiTI 或你自己的流程)。它不是替代品;它是让你的现有流程具备 AI 就绪能力的层。
什么是 ATHF?
ATHF 为威胁狩猎项目提供结构和持久性。它是一个基于 Markdown 的框架,可以:
- 使用 LOCK 模式(Learn → Observe → Check → Keep)记录狩猎
- 维护可搜索的过往调查仓库
- 使 AI 助手能够引用你的环境和先前工作
- 与任何 SIEM/EDR 平台配合使用
- 新增: 包含 AI 驱动的研究和假设生成智能体(v0.3.0+)
问题所在
大多数威胁狩猎项目在狩猎结束后就丢失了宝贵的上下文。笔记散落在 Slack 或工单中,查询写一次就被遗忘,经验教训只存在于分析师的头脑中。
即使是 AI 工具,每次也都从零开始,无法访问你的环境、数据或过往狩猎记录。
ATHF 通过为你的狩猎提供结构、持久性和上下文来改变这一点。
阅读更多: docs/why-athf.md
LOCK 模式
每一次威胁狩猎都遵循相同的基本循环:Learn → Observe → Check → Keep。

- Learn(学习): 从威胁情报、告警或异常中收集上下文
- Observe(观察): 形成关于对手行为的假设
- Check(检查): 使用针对性查询检验假设
- Keep(保留): 记录发现和经验教训
为什么是 LOCK? 它足够小,便于使用;又足够严格,便于智能体解释。通过以这种格式记录每一次狩猎,ATHF 使 AI 助手能够回忆先前工作,并基于过往结果建议改进的查询。
阅读更多: docs/lock-pattern.md
智能体狩猎的五个级别
ATHF 定义了一个简单的成熟度模型。每个级别都建立在前一个级别之上。
大多数团队将停留在级别 1–2。超出此范围的一切都是可选的成熟度。

| 级别 | 能力 | 你将获得 |
|---|---|---|
| 0 | 临时性 | 狩猎存在于 Slack、工单或分析师笔记中 |
| 1 | 已记录 | 使用 LOCK 的持久化狩猎记录 |
| 2 | 可搜索 | AI 读取并回忆你的狩猎 |
| 3 | 生成式 | AI 通过 MCP 工具执行查询,开展研究 |
| 4 | 智能体 | 自主智能体监控并行动,生成假设 |
级别 1: 一天内即可运行 级别 2: 一周内即可运行 级别 3: 2-4 周(可选) 级别 4: 1-3 个月(可选)
阅读更多: docs/maturity-model.md
🚀 快速开始
选项 1:从 PyPI 安装(推荐)
# Install ATHF
pip install agentic-threat-hunting-framework
# Initialize your hunt program
athf init
# NEW: Conduct research before hunting (5-skill methodology)
athf research new --topic "LSASS dumping" --technique T1003.001
# Create your first hunt (link to research)
athf hunt new --technique T1003.001 --title "LSASS Credential Dumping" --research R-0001
选项 2:从源码安装(开发)
# Clone and install from source
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
pip install -e .
# Initialize and start hunting
athf init
athf hunt new --technique T1003.001
选项 3:纯 Markdown(无需安装)
# Clone the repository
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
# Copy a template and start documenting
mkdir -p hunts
cp athf/data/templates/HUNT_LOCK.md hunts/H-0001.md
# Customize AGENTS.md with your environment
# Add your SIEM, EDR, and data sources
选择你的 AI 助手: Claude Code、GitHub Copilot 或 Cursor——任何能够读取你仓库文件的工具。
完整指南: docs/getting-started.md
🔧 CLI 命令
ATHF 包含一个功能齐全的 CLI,用于管理你的狩猎。以下是快速参考:
初始化工作区
athf init # Interactive setup
athf init --non-interactive # Use defaults
研究与假设生成(v0.3.0 新增)
# Conduct thorough pre-hunt research (15-20 min)
athf research new --topic "LSASS dumping" --technique T1003.001
# Quick research for urgent hunts (5 min)
athf research new --topic "Pass-the-Hash" --depth basic
# Generate AI-powered hypothesis from threat intel
athf agent run hypothesis-generator --threat-intel "APT29 targeting SaaS"
# List research and agents
athf research list
athf agent list
创建狩猎
athf hunt new # Interactive mode
athf hunt new \
--technique T1003.001 \
--title "LSASS Dumping Detection" \
--platform windows \
--hunt-type baseline \
--research R-0001 # Link to research document
# --hunt-type: hypothesis (default) | baseline | model-assisted
列出与搜索
athf hunt list # Show all hunts
athf hunt list --status completed # Filter by status
athf hunt list --directory test # Filter by environment (test/production)
athf hunt list --hunt-type baseline # Filter by hunt category
athf hunt list --output json # JSON output
athf hunt search "kerberoasting" # Full-text search
athf hunt search "credential" --directory production # Search with directory filter
athf research search "credential" # Search research docs
验证与统计
athf hunt validate # Validate all hunts
athf hunt validate H-0001 # Validate specific hunt
athf hunt stats # Show statistics (incl. hunts by type)
athf hunt stats --by hunt_type --status completed --output json # Category breakdown
athf hunt coverage # MITRE ATT&CK coverage
athf research stats # Research metrics
ATT&CK 数据管理(v0.11.0 新增)
# Install STIX support (optional)
pip install 'agentic-threat-hunting-framework[attack]'
# Download live ATT&CK data (835+ techniques with full metadata)
athf attack update
# Check provider status
athf attack status
# Look up technique metadata
athf attack lookup T1003.001
# List techniques for a tactic
athf attack techniques credential-access
如果没有 mitreattack-python,ATHF 使用硬编码的 v14 回退数据(14 个战术,近似计数)。有了它,你将获得完整的技术元数据:平台、数据源、子技术以及准确的计数。
MCP 服务器(v0.11.0 新增)
# Install MCP dependencies
pip install 'agentic-threat-hunting-framework[mcp]'
# Start MCP server (for Claude Code, Copilot, Cursor, etc.)
athf mcp serve --workspace /path/to/hunts
在 ~/.claude/mcp-servers.json 中配置:
{
"athf": {
"command": "athf-mcp",
"env": { "ATHF_WORKSPACE": "/path/to/your/hunts" }
}
}
独立的 athf-mcp 入口点会从 cwd 或 ATHF_WORKSPACE 环境变量自动检测你的工作区。使用 athf mcp serve --workspace /path 指定显式路径。
安全提示:
sse和streamable-http传输绑定到127.0.0.1,并且未经身份验证。每个工具都会读取你的整个工作区,有些还会以你的费用调用 LLM 智能体。只有在需要绑定可路由接口时才传入--host,并且在这种情况下要在前面放置一个身份验证代理。默认的stdio传输完全不打开套接字。
暴露 17 个工具:狩猎管理、语义搜索、ATT&CK 覆盖、研究、调查以及 AI 驱动的假设生成——全部可直接从你的 AI 编码助手访问。
完整文档: CLI Reference
📺 实际演示

观看 ATHF 的实际运行:在 60 秒内初始化工作区、创建狩猎并探索你的威胁狩猎目录。
安装
请参阅上方的快速开始部分了解安装选项(PyPI、源码或纯 Markdown)。
先决条件:
- Python 3.11 或更高版本(用于 CLI 选项)
- 你最喜欢的 AI 代码助手