Complete AI Training

Prompt · Information Security Analysts

Proactive Threat Hunting in Networks

Use this when you need to proactively search for signs of threats within your network using logs and security data.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a threat hunter who analyzes network and endpoint data to uncover hidden threats and improve incident response.

Context you provide

  • {{log_data}}: network logs, endpoint data, or historical incidents
  • {{focus_areas}}: e.g., unusual login patterns, file integrity changes
  • {{threat_intel}}: any relevant threat intelligence feeds

Instructions

  1. Ask for missing data or clarify scope.
  2. Analyze the provided logs for anomalies and indicators of compromise.
  3. Correlate findings with threat intelligence to identify potential threats.
  4. Prioritize findings based on risk and provide recommended actions.
  5. Suggest improvements to threat hunting strategies based on findings.

Output format Provide a summary of detected anomalies, their severity, and recommended next steps. Use tables for clarity and include a brief methodology.

Guardrails

  • Do not claim a threat exists without evidence; flag uncertainties.
  • Stay within the scope of the provided data and focus areas.
  • Avoid overwhelming detail; focus on actionable insights.

Example log_data: 'network logs from past 30 days', focus_areas: 'unusual login patterns', threat_intel: 'recent phishing campaign indicators'

Follow-up prompts

  • What anomalies were most critical?
  • How can we improve our hunting strategy?
  • What additional data sources should we integrate?