Archives
- 24 Aug DNS Hunting - The Undervalued Data Source
- 23 Aug Network Hunting Fundamentals
- 22 Aug Phase 6 Capstone - Endpoint Hunt Operation
- 21 Aug Malware Analysis for Threat Hunters
- 20 Aug Ransomware Hunting Before Encryption
- 19 Aug Linux Rootkits, Reverse Shells, and Persistence
- 18 Aug Linux Threat Hunting Fundamentals
- 17 Aug Hunting BloodHound-Style Attack Paths
- 16 Aug Active Directory Threat Hunting Guide
- 15 Aug Windows Credential Hunting
- 14 Aug Windows Persistence Hunting
- 13 Aug Hunting Fileless Malware in Memory
- 12 Aug Hunting LOLBAS Abuse
- 11 Aug Reading Windows Process Trees
- 10 Aug Building a Detection-as-Code Pipeline
- 09 Aug YARA Rules for Threat Hunters
- 08 Aug Writing Portable Sigma Rules
- 07 Aug Wireshark for Threat Hunters
- 06 Aug Suricata as a Hunt Data Source
- 05 Aug Network Hunting with Zeek
- 04 Aug EDR Telemetry: What Your Agent Is Really Telling You
- 03 Aug Microsoft Defender XDR Advanced Hunting with KQL
- 02 Aug Microsoft Sentinel KQL Mastery for Hunters
- 01 Aug Elastic EQL and KQL Hunting Guide
- 31 Jul Splunk SPL Queries Every Threat Hunter Needs
- 30 Jul PowerShell Logging for Threat Hunters
- 29 Jul Windows Security Event Log Hunting Guide
- 28 Jul Sysmon Deep Dive: Registry, Pipe, WMI, DNS Events
- 27 Jul Sysmon Deep Dive: Process, Network, File Events
- 26 Jul Sysmon Setup and Tuning for Threat Hunters
- 25 Jul Building a Complete ATT&CK Hunt Playbook
- 24 Jul Hunting Ransomware, Sabotage, and Impact-Stage Attacks
- 23 Jul Hunting Exfiltration Before It's Too Late
- 22 Jul Hunting DNS Tunneling, DGA, and Covert C2
- 21 Jul Hunting C2 Finding Attacker Callback Channels
- 20 Jul Hunting Collection: Catching Data Staging Before It Leaves
- 19 Jul Hunting WMI, PsExec, and Remote Execution: Where Admin Tools Turn Malicious
- 18 Jul Hunting Lateral Movement: Following Attackers Across Your Network
- 17 Jul Hunting Discovery: What Attackers Map Before They Move
- 16 Jul AI and Threat Hunting: Augmentation, Not Replacement
- 16 Jul Hunting Kerberos Attacks: Golden Tickets, Silver Tickets, and AS-REP Roasting
- 15 Jul Hunting Credential Access: Catching the Password Thief
- 14 Jul Hunting Process Injection: The Cornerstone of Modern Evasion
- 13 Jul Hunting Defense Evasion: The Hardest Tactic to Detect
- 12 Jul Hunting Privilege Escalation: Detecting the Climb to SYSTEM
- 11 Jul Hunting Persistence: A Deep Dive Into Registry, Startup, and WMI
- 10 Jul Hunting Persistence: Finding the Footholds That Survive a Reboot
- 09 Jul Hunting Execution: PowerShell and Living-Off-the-Land Binaries
- 08 Jul Hunting Execution: How Attackers Actually Run Their Code
- 07 Jul Hunting Initial Access Part 2: Supply Chain and Trusted Relationships
- 06 Jul Hunting Initial Access: Catching the Breach Before It Begins
- 05 Jul Hunting Resource Development: Find Infrastructure Before It Is Used
- 04 Jul Hunting Reconnaissance: Finding Pre-Intrusion Warning Signals
- 03 Jul MITRE ATT&CK for Hunters: Beyond the Matrix Poster
- 02 Jul Phase 3 Capstone: Run Three Hunts, Three Different Ways
- 01 Jul Structured Analytic Techniques for Threat Hunters
- 30 Jun TTP-Based Hunting: Working at the Top of the Pyramid
- 29 Jun Behavior-Based Hunting: Finding Threats Without a Signature
- 28 Jun IOC-Based Hunting, Done Right
- 27 Jun Intelligence-Driven Hunting: A Complete Framework
- 26 Jun Creating Hunt Hypotheses From Risk Analysis
- 25 Jun Modeling Adversary Behavior to Generate Hunt Hypotheses
- 24 Jun Mining Your Own Environment for Hunt Hypotheses
- 23 Jun Turning Threat Intelligence Into Real Hunt Hypotheses
- 22 Jun What a Hunt Hypothesis Is—and What It Is Not
- 21 Jun The Threat Hunting Lifecycle, Step by Step
- 20 Jun Phase 2 Capstone: Threat Landscape Analysis for a Target Sector
- 19 Jun The Diamond Model: Give Your Hunts Structure
- 18 Jun The Cyber Kill Chain, Read as a Hunting Map
- 17 Jun Building a Threat Intelligence Function That Actually Feeds Your Hunts
- 16 Jun Commercial Threat Intelligence Platforms: What Is Worth Paying For?
- 15 Jun OSINT for Threat Hunters: Free Intelligence, Used Well
- 14 Jun CTI Fundamentals: Strategic, Operational, and Tactical Intelligence
- 13 Jun Hunting Ransomware Across Every Phase of the Attack
- 12 Jun Studying Real APT Campaigns for Hunt-Ready Intelligence
- 11 Jun The Modern Threat Landscape: Who Is Actually Out There?
- 10 Jun Phase 1 Capstone: Design Your Threat Hunting Program
- 09 Jun Threat Hunting Documentation That Actually Gets Used
- 08 Jun Your First Hunt, Start to Finish
- 07 Jun Threat Hunting Program Models, From Solo to Enterprise
- 06 Jun Mapping the SOC Data Ecosystem
- 05 Jun Build a Threat Hunting Home Lab: A Safe, Practical Guide
- 04 Jun The Threat Hunting Maturity Model, Explained Honestly
- 03 Jun Threat Hunting vs. Detection Engineering vs. Incident Response
- 02 Jun The Threat Hunting Mindset: Think in Attack Paths
- 01 Jun What Is Threat Hunting? A Practical Introduction