<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.threathuntlabs.com/</id><title>ThreatHuntLabs</title><subtitle>Practical threat hunting field notes, detection ideas, and guided investigations for defenders who want to understand attacker behavior.</subtitle> <updated>2026-08-24T13:40:12+05:30</updated> <author> <name>ThreatHuntLabs</name> <uri>https://blog.threathuntlabs.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.threathuntlabs.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://blog.threathuntlabs.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 ThreatHuntLabs </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>DNS Hunting - The Undervalued Data Source</title><link href="https://blog.threathuntlabs.com/posts/DNS-Hunting-The-Undervalued-Data-Source/" rel="alternate" type="text/html" title="DNS Hunting - The Undervalued Data Source" /><published>2026-08-24T12:00:00+05:30</published> <updated>2026-07-15T20:04:17+05:30</updated> <id>https://blog.threathuntlabs.com/posts/DNS-Hunting-The-Undervalued-Data-Source/</id> <content type="text/html" src="https://blog.threathuntlabs.com/posts/DNS-Hunting-The-Undervalued-Data-Source/" /> <author> <name>ThreatHuntLabs</name> </author> <category term="Threat Hunting" /> <category term="Network Security" /> <summary>DNS logs are cheap, rich, and mostly ignored. Here's how to extract serious threat intelligence from query data most teams never review.</summary> </entry> <entry><title>Network Hunting Fundamentals</title><link href="https://blog.threathuntlabs.com/posts/Network-Hunting-Fundamentals/" rel="alternate" type="text/html" title="Network Hunting Fundamentals" /><published>2026-08-23T12:00:00+05:30</published> <updated>2026-07-15T20:04:17+05:30</updated> <id>https://blog.threathuntlabs.com/posts/Network-Hunting-Fundamentals/</id> <content type="text/html" src="https://blog.threathuntlabs.com/posts/Network-Hunting-Fundamentals/" /> <author> <name>ThreatHuntLabs</name> </author> <category term="Threat Hunting" /> <category term="Network Security" /> <summary>Core network hunting skills across NetFlow, packet capture, proxy logs, and firewall data what your traffic is actually telling you.</summary> </entry> <entry><title>Phase 6 Capstone - Endpoint Hunt Operation</title><link href="https://blog.threathuntlabs.com/posts/Phase-6-Capstone-Endpoint-Hunt-Operation/" rel="alternate" type="text/html" title="Phase 6 Capstone - Endpoint Hunt Operation" /><published>2026-08-22T12:00:00+05:30</published> <updated>2026-07-15T20:04:17+05:30</updated> <id>https://blog.threathuntlabs.com/posts/Phase-6-Capstone-Endpoint-Hunt-Operation/</id> <content type="text/html" src="https://blog.threathuntlabs.com/posts/Phase-6-Capstone-Endpoint-Hunt-Operation/" /> <author> <name>ThreatHuntLabs</name> </author> <category term="Threat Hunting" /> <summary>Run a full endpoint hunt against a simulated post-compromise environment the capstone that ties static skills into a real operation.</summary> </entry> <entry><title>Malware Analysis for Threat Hunters</title><link href="https://blog.threathuntlabs.com/posts/Malware-Analysis-for-Threat-Hunters/" rel="alternate" type="text/html" title="Malware Analysis for Threat Hunters" /><published>2026-08-21T12:00:00+05:30</published> <updated>2026-07-15T20:04:17+05:30</updated> <id>https://blog.threathuntlabs.com/posts/Malware-Analysis-for-Threat-Hunters/</id> <content type="text/html" src="https://blog.threathuntlabs.com/posts/Malware-Analysis-for-Threat-Hunters/" /> <author> <name>ThreatHuntLabs</name> </author> <category term="Threat Hunting" /> <summary>Hunters don't need to reverse full malware families they need hunt-relevant intel fast. Here's the static and dynamic workflow that gets it.</summary> </entry> <entry><title>Ransomware Hunting Before Encryption</title><link href="https://blog.threathuntlabs.com/posts/Ransomware-Hunting-Before-Encryption/" rel="alternate" type="text/html" title="Ransomware Hunting Before Encryption" /><published>2026-08-20T12:00:00+05:30</published> <updated>2026-07-15T20:04:17+05:30</updated> <id>https://blog.threathuntlabs.com/posts/Ransomware-Hunting-Before-Encryption/</id> <content type="text/html" src="https://blog.threathuntlabs.com/posts/Ransomware-Hunting-Before-Encryption/" /> <author> <name>ThreatHuntLabs</name> </author> <category term="Threat Hunting" /> <summary>Ransomware has a loud, predictable buildup before encryption. Here's how to hunt the precursor activity and stop it in time.</summary> </entry> </feed>
