{ "schema": "skillstore.package/v1", "id": "yara-hunting", "name": "YARA Threat Hunting", "description": "IOC sweep and malware-oriented hunting workflow using YARA on SANS SIFT, with false-positive testing and evidence correlation.", "entry": "SKILL.md", "source": { "repository": "https://github.com/teamdfir/protocol-sift/tree/main/skills/yara-hunting", "author": "Rob Lee / teamdfir" }, "tags": ["dfir", "yara", "threat-hunting", "ioc", "malware", "sift"], "compatibility": ["SANS SIFT Workstation", "filesystem-capable AI agent"] }