Threat Hunting
Proactive cybersecurity practice of searching through networks, endpoints, and datasets to hunt for malicious, suspicious, or risky activities that have evaded detection by existing security tools.
Threat Hunting Methodologies
Hypothesis-Driven Hunting
Structured hunting based on threat intelligence, adversary TTPs, and analytics-driven hypotheses about potential malicious activity.
Intelligence-Driven Hunting
Hunting activities driven by specific threat intelligence indicators (IOCs, TTPs) related to known adversaries or campaigns.
Behavioral & Anomaly-Based Hunting
Detection of anomalous behaviors and deviations from established baselines that may indicate compromised systems or insider threats.
Event Clustering & Correlation Hunting
Grouping related events and applying temporal analysis to identify attack campaigns and lateral movement patterns.
Malware & Reverse Engineering Hunting
Analysis of suspicious files, memory dumps, and network traffic to identify malware infections and command-and-control communications.
Threat Hunting Frameworks
Adoption of established frameworks like PTES, MITRE ATT&CK, and the Diamond Model to structure hunting activities.
Threat Hunting Process & Workflow
The threat hunting lifecycle consists of several key phases:
The Hunting Cycle
Trigger → Hypothesis → Investigation → Discovery/Resolution → Documentation → Enrichment → Automation
Data Sources & Telemetry
Network traffic, endpoint logs, authentication records, proxy logs, DNS queries, and cloud service logs as primary data sources for hunting.
Hunting Tools & Techniques
AI-Assisted Hunting
Leveraging artificial intelligence and behavioral models to surface anomalies that warrant human investigation.
Open Source Platforms
Building hunting workflows on open source security platforms with transparent, extensible detection capabilities.
Query & Investigation
Structured querying of telemetry and log data to test hypotheses and trace attacker activity end to end.