Nebulock-Inc/agentic-threat-hunting-framework

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

59
/ 100
Established

This framework helps cybersecurity teams like threat hunters and security analysts effectively document and manage their investigations. It takes your raw threat intelligence, security alerts, and observed anomalies as input, and produces structured, searchable records of your past hunts. These records can then be used to inform future investigations and train AI assistants to work with your specific environment.

205 stars. Available on PyPI.

Use this if your threat hunting program struggles to retain context from past investigations, leading to repeated work or missed insights.

Not ideal if you're looking for an automated SIEM/EDR replacement rather than a system to structure and enhance your existing hunting processes.

threat-hunting cybersecurity security-operations incident-response security-analysis
Maintenance 10 / 25
Adoption 10 / 25
Maturity 22 / 25
Community 17 / 25

How are scores calculated?

Stars

205

Forks

29

Language

Python

License

MIT

Last pushed

Mar 09, 2026

Commits (30d)

0

Dependencies

6

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/agents/Nebulock-Inc/agentic-threat-hunting-framework"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.