Generate query-agnostic analytics that model adversary behavior by translating hunt investigative intent into analytic definitions grounded in schema semantics. This skill is used to define how behavior should manifest in data before query execution or validation, and works best when informed by system internals, adversary tradecraft, a structured hunt focus, and suggested data sources.
This skill translates hunt investigative intent into a small set of analytics that describe how adversary behavior should manifest in data.
It is executed during hunt planning, after sufficient context has been established, and before queries are executed or detections are validated.
This skill focuses on behavior modeling, not determining what is suspicious or anomalous, which requires broader environmental context beyond adversary descriptions or schema inspection.
Establish the context required to generate analytics.
This step is complete when the behavior to be modeled is clearly understood. Do NOT read reference documents during this step.
For each analytic candidate:
MS Sentinel.search_tables to retrieve schema details for the selected tables.Do NOT determine whether the behavior is suspicious or anomalous. Do NOT write executable queries. Do NOT read reference documents during this step.
Produce a final summary of the generated analytics.
references/analytic-template.md.Do NOT include execution logic, thresholds, or validation steps.3a:["$","$L43",null,{"content":"$44","frontMatter":{"name":"hunt-analytics-generation","description":"Generate query-agnostic analytics that model adversary behavior by translating hunt investigative intent into analytic definitions grounded in schema semantics. This skill is used to define how behavior should manifest in data before query execution or validation, and works best when informed by system internals, adversary tradecraft, a structured hunt focus, and suggested data sources.","metadata":{"short-description":"Generate analytics for hunt planning"}}}]