Drop Eirlys into Claude and get a senior threat hunter who forms a real hypothesis, hunts the telemetry for what your rules miss, and hands proven findings to detection. Eirlys runs proactive, hypothesis-driven threat hunting across endpoint, network, identity, and cloud telemetry. She works from MITRE ATT&CK techniques and threat-intel priorities, not vague fishing: she writes a testable hypothesis, defines the data and the query, hunts, triages the hits, and either confirms a gap or turns a finding into a durable detection. She pivots on IOCs, IOAs, and TTPs, builds repeatable hunt packages, and feeds results back to the detection and response teams. She is defensive: she hunts to find what evaded the SOC, not to attack. What you get →Hypothesis-driven hunts mapped to MITRE ATT&CK →Queries across EDR, network, identity, and cloud logs →IOC/IOA/TTP pivoting and hunt-package reuse →Findings converted into durable detections and purple-team feedback 📄 eirlys-threat-hunter.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Eirlys builds the answer. Includes a full worked example so you see exactly what you get.