返回更新列表
新发布Jul 31, 2026

agentic-threat-hunting-framework v0.18.0

ATHF是一个用于自主威胁狩猎的框架——构建能够记忆、学习并以更高自主性行动的系统。

分享

智能体威胁狩猎框架(ATHF)

ATHF Logo

PyPI version PyPI downloads Python Version License: MIT GitHub stars

快速开始 • 安装 • 文档 • 示例

为你的威胁狩猎项目赋予记忆与自主能力。

智能体威胁狩猎框架(ATHF) 是你的威胁狩猎项目的记忆与自动化层。它为你的狩猎提供结构、持久性和上下文——让每一次过往调查都能被人类和 AI 访问。

ATHF 可与任何狩猎方法论配合使用(PEAK、TaHiTI 或你自己的流程)。它不是替代品;它是让你的现有流程具备 AI 就绪能力的层。

什么是 ATHF?

ATHF 为威胁狩猎项目提供结构和持久性。它是一个基于 Markdown 的框架,可以:

  • 使用 LOCK 模式(Learn → Observe → Check → Keep)记录狩猎
  • 维护可搜索的过往调查仓库
  • 使 AI 助手能够引用你的环境和先前工作
  • 与任何 SIEM/EDR 平台配合使用
  • 新增: 包含 AI 驱动的研究和假设生成智能体(v0.3.0+)

问题所在

大多数威胁狩猎项目在狩猎结束后就丢失了宝贵的上下文。笔记散落在 Slack 或工单中,查询写一次就被遗忘,经验教训只存在于分析师的头脑中。

即使是 AI 工具,每次也都从零开始,无法访问你的环境、数据或过往狩猎记录。

ATHF 通过为你的狩猎提供结构、持久性和上下文来改变这一点。

阅读更多: docs/why-athf.md

LOCK 模式

每一次威胁狩猎都遵循相同的基本循环:Learn → Observe → Check → Keep。

The LOCK Pattern

  • Learn(学习): 从威胁情报、告警或异常中收集上下文
  • Observe(观察): 形成关于对手行为的假设
  • Check(检查): 使用针对性查询检验假设
  • Keep(保留): 记录发现和经验教训

为什么是 LOCK? 它足够小,便于使用;又足够严格,便于智能体解释。通过以这种格式记录每一次狩猎,ATHF 使 AI 助手能够回忆先前工作,并基于过往结果建议改进的查询。

阅读更多: docs/lock-pattern.md

智能体狩猎的五个级别

ATHF 定义了一个简单的成熟度模型。每个级别都建立在前一个级别之上。

大多数团队将停留在级别 1–2。超出此范围的一切都是可选的成熟度。

The Five Levels

级别能力你将获得
0临时性狩猎存在于 Slack、工单或分析师笔记中
1已记录使用 LOCK 的持久化狩猎记录
2可搜索AI 读取并回忆你的狩猎
3生成式AI 通过 MCP 工具执行查询,开展研究
4智能体自主智能体监控并行动,生成假设

级别 1: 一天内即可运行 级别 2: 一周内即可运行 级别 3: 2-4 周(可选) 级别 4: 1-3 个月(可选)

阅读更多: docs/maturity-model.md

🚀 快速开始

选项 1:从 PyPI 安装(推荐)

# Install ATHF
pip install agentic-threat-hunting-framework

# Initialize your hunt program
athf init

# NEW: Conduct research before hunting (5-skill methodology)
athf research new --topic "LSASS dumping" --technique T1003.001

# Create your first hunt (link to research)
athf hunt new --technique T1003.001 --title "LSASS Credential Dumping" --research R-0001

选项 2:从源码安装(开发)

# Clone and install from source
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework
pip install -e .

# Initialize and start hunting
athf init
athf hunt new --technique T1003.001

选项 3:纯 Markdown(无需安装)

# Clone the repository
git clone https://github.com/Nebulock-Inc/agentic-threat-hunting-framework
cd agentic-threat-hunting-framework

# Copy a template and start documenting
mkdir -p hunts
cp athf/data/templates/HUNT_LOCK.md hunts/H-0001.md

# Customize AGENTS.md with your environment
# Add your SIEM, EDR, and data sources

选择你的 AI 助手: Claude Code、GitHub Copilot 或 Cursor——任何能够读取你仓库文件的工具。

完整指南: docs/getting-started.md

🔧 CLI 命令

ATHF 包含一个功能齐全的 CLI,用于管理你的狩猎。以下是快速参考:

初始化工作区

athf init                           # Interactive setup
athf init --non-interactive         # Use defaults

研究与假设生成(v0.3.0 新增)

# Conduct thorough pre-hunt research (15-20 min)
athf research new --topic "LSASS dumping" --technique T1003.001

# Quick research for urgent hunts (5 min)
athf research new --topic "Pass-the-Hash" --depth basic

# Generate AI-powered hypothesis from threat intel
athf agent run hypothesis-generator --threat-intel "APT29 targeting SaaS"

# List research and agents
athf research list
athf agent list

创建狩猎

athf hunt new                       # Interactive mode
athf hunt new \
  --technique T1003.001 \
  --title "LSASS Dumping Detection" \
  --platform windows \
  --hunt-type baseline \
  --research R-0001                 # Link to research document
# --hunt-type: hypothesis (default) | baseline | model-assisted

列出与搜索

athf hunt list                      # Show all hunts
athf hunt list --status completed   # Filter by status
athf hunt list --directory test     # Filter by environment (test/production)
athf hunt list --hunt-type baseline # Filter by hunt category
athf hunt list --output json        # JSON output
athf hunt search "kerberoasting"    # Full-text search
athf hunt search "credential" --directory production  # Search with directory filter
athf research search "credential"   # Search research docs

验证与统计

athf hunt validate                  # Validate all hunts
athf hunt validate H-0001           # Validate specific hunt
athf hunt stats                     # Show statistics (incl. hunts by type)
athf hunt stats --by hunt_type --status completed --output json  # Category breakdown
athf hunt coverage                  # MITRE ATT&CK coverage
athf research stats                 # Research metrics

ATT&CK 数据管理(v0.11.0 新增)

# Install STIX support (optional)
pip install 'agentic-threat-hunting-framework[attack]'

# Download live ATT&CK data (835+ techniques with full metadata)
athf attack update

# Check provider status
athf attack status

# Look up technique metadata
athf attack lookup T1003.001

# List techniques for a tactic
athf attack techniques credential-access

如果没有 mitreattack-python,ATHF 使用硬编码的 v14 回退数据(14 个战术,近似计数)。有了它,你将获得完整的技术元数据:平台、数据源、子技术以及准确的计数。

MCP 服务器(v0.11.0 新增)

# Install MCP dependencies
pip install 'agentic-threat-hunting-framework[mcp]'

# Start MCP server (for Claude Code, Copilot, Cursor, etc.)
athf mcp serve --workspace /path/to/hunts

在 ~/.claude/mcp-servers.json 中配置:

{
  "athf": {
    "command": "athf-mcp",
    "env": { "ATHF_WORKSPACE": "/path/to/your/hunts" }
  }
}

独立的 athf-mcp 入口点会从 cwd 或 ATHF_WORKSPACE 环境变量自动检测你的工作区。使用 athf mcp serve --workspace /path 指定显式路径。

安全提示: sse 和 streamable-http 传输绑定到 127.0.0.1,并且未经身份验证。每个工具都会读取你的整个工作区,有些还会以你的费用调用 LLM 智能体。只有在需要绑定可路由接口时才传入 --host,并且在这种情况下要在前面放置一个身份验证代理。默认的 stdio 传输完全不打开套接字。

暴露 17 个工具:狩猎管理、语义搜索、ATT&CK 覆盖、研究、调查以及 AI 驱动的假设生成——全部可直接从你的 AI 编码助手访问。

完整文档: CLI Reference

📺 实际演示

ATHF Demo

观看 ATHF 的实际运行:在 60 秒内初始化工作区、创建狩猎并探索你的威胁狩猎目录。

查看示例狩猎 →

安装

请参阅上方的快速开始部分了解安装选项(PyPI、源码或纯 Markdown)。

先决条件:

  • Python 3.11 或更高版本(用于 CLI 选项)
  • 你最喜欢的 AI 代码助手

文档

核心概念

分类