MITRE ATT&CK 25
- Building a Complete ATT&CK Hunt Playbook
- Hunting Ransomware, Sabotage, and Impact-Stage Attacks
- Hunting Exfiltration Before It's Too Late
- Hunting DNS Tunneling, DGA, and Covert C2
- Hunting C2 Finding Attacker Callback Channels
- Hunting Collection: Catching Data Staging Before It Leaves
- Hunting WMI, PsExec, and Remote Execution: Where Admin Tools Turn Malicious
- Hunting Lateral Movement: Following Attackers Across Your Network
- Hunting Discovery: What Attackers Map Before They Move
- Hunting Kerberos Attacks: Golden Tickets, Silver Tickets, and AS-REP Roasting
- Hunting Credential Access: Catching the Password Thief
- Hunting Process Injection: The Cornerstone of Modern Evasion
- Hunting Defense Evasion: The Hardest Tactic to Detect
- Hunting Privilege Escalation: Detecting the Climb to SYSTEM
- Hunting Persistence: A Deep Dive Into Registry, Startup, and WMI
- Hunting Persistence: Finding the Footholds That Survive a Reboot
- Hunting Execution: PowerShell and Living-Off-the-Land Binaries
- Hunting Execution: How Attackers Actually Run Their Code
- Hunting Initial Access Part 2: Supply Chain and Trusted Relationships
- Hunting Initial Access: Catching the Breach Before It Begins
- Hunting Resource Development: Find Infrastructure Before It Is Used
- Hunting Reconnaissance: Finding Pre-Intrusion Warning Signals
- MITRE ATT&CK for Hunters: Beyond the Matrix Poster
- Phase 3 Capstone: Run Three Hunts, Three Different Ways
- Structured Analytic Techniques for Threat Hunters