Threat Hunting 86
- DNS Hunting - The Undervalued Data Source
- Network Hunting Fundamentals
- Phase 6 Capstone - Endpoint Hunt Operation
- Malware Analysis for Threat Hunters
- Ransomware Hunting Before Encryption
- Linux Rootkits, Reverse Shells, and Persistence
- Linux Threat Hunting Fundamentals
- Hunting BloodHound-Style Attack Paths
- Active Directory Threat Hunting Guide
- Windows Credential Hunting
- Windows Persistence Hunting
- Hunting Fileless Malware in Memory
- Hunting LOLBAS Abuse
- Reading Windows Process Trees
- Building a Detection-as-Code Pipeline
- YARA Rules for Threat Hunters
- Writing Portable Sigma Rules
- Wireshark for Threat Hunters
- Suricata as a Hunt Data Source
- Network Hunting with Zeek
- EDR Telemetry: What Your Agent Is Really Telling You
- Microsoft Defender XDR Advanced Hunting with KQL
- Microsoft Sentinel KQL Mastery for Hunters
- Elastic EQL and KQL Hunting Guide
- Splunk SPL Queries Every Threat Hunter Needs
- PowerShell Logging for Threat Hunters
- Windows Security Event Log Hunting Guide
- Sysmon Deep Dive: Registry, Pipe, WMI, DNS Events
- Sysmon Deep Dive: Process, Network, File Events
- Sysmon Setup and Tuning for Threat Hunters
- Building a Complete ATT&CK Hunt Playbook
- Hunting Ransomware, Sabotage, and Impact-Stage Attacks
- Hunting Exfiltration Before It's Too Late
- Hunting DNS Tunneling, DGA, and Covert C2
- Hunting C2 Finding Attacker Callback Channels
- Hunting Collection: Catching Data Staging Before It Leaves
- Hunting WMI, PsExec, and Remote Execution: Where Admin Tools Turn Malicious
- Hunting Lateral Movement: Following Attackers Across Your Network
- Hunting Discovery: What Attackers Map Before They Move
- AI and Threat Hunting: Augmentation, Not Replacement
- Hunting Kerberos Attacks: Golden Tickets, Silver Tickets, and AS-REP Roasting
- Hunting Credential Access: Catching the Password Thief
- Hunting Process Injection: The Cornerstone of Modern Evasion
- Hunting Defense Evasion: The Hardest Tactic to Detect
- Hunting Privilege Escalation: Detecting the Climb to SYSTEM
- Hunting Persistence: A Deep Dive Into Registry, Startup, and WMI
- Hunting Persistence: Finding the Footholds That Survive a Reboot
- Hunting Execution: PowerShell and Living-Off-the-Land Binaries
- Hunting Execution: How Attackers Actually Run Their Code
- Hunting Initial Access Part 2: Supply Chain and Trusted Relationships
- Hunting Initial Access: Catching the Breach Before It Begins
- Hunting Resource Development: Find Infrastructure Before It Is Used
- Hunting Reconnaissance: Finding Pre-Intrusion Warning Signals
- MITRE ATT&CK for Hunters: Beyond the Matrix Poster
- Phase 3 Capstone: Run Three Hunts, Three Different Ways
- Structured Analytic Techniques for Threat Hunters
- TTP-Based Hunting: Working at the Top of the Pyramid
- Behavior-Based Hunting: Finding Threats Without a Signature
- IOC-Based Hunting, Done Right
- Intelligence-Driven Hunting: A Complete Framework
- Creating Hunt Hypotheses From Risk Analysis
- Modeling Adversary Behavior to Generate Hunt Hypotheses
- Mining Your Own Environment for Hunt Hypotheses
- Turning Threat Intelligence Into Real Hunt Hypotheses
- What a Hunt Hypothesis Is—and What It Is Not
- The Threat Hunting Lifecycle, Step by Step
- Phase 2 Capstone: Threat Landscape Analysis for a Target Sector
- The Diamond Model: Give Your Hunts Structure
- The Cyber Kill Chain, Read as a Hunting Map
- Building a Threat Intelligence Function That Actually Feeds Your Hunts
- Commercial Threat Intelligence Platforms: What Is Worth Paying For?
- OSINT for Threat Hunters: Free Intelligence, Used Well
- CTI Fundamentals: Strategic, Operational, and Tactical Intelligence
- Hunting Ransomware Across Every Phase of the Attack
- Studying Real APT Campaigns for Hunt-Ready Intelligence
- The Modern Threat Landscape: Who Is Actually Out There?
- Phase 1 Capstone: Design Your Threat Hunting Program
- Threat Hunting Documentation That Actually Gets Used
- Your First Hunt, Start to Finish
- Threat Hunting Program Models, From Solo to Enterprise
- Mapping the SOC Data Ecosystem
- Build a Threat Hunting Home Lab: A Safe, Practical Guide
- The Threat Hunting Maturity Model, Explained Honestly
- Threat Hunting vs. Detection Engineering vs. Incident Response
- The Threat Hunting Mindset: Think in Attack Paths
- What Is Threat Hunting? A Practical Introduction