Tags Active Directory2 adversary mindset1 adversary modeling1 analysis techniques1 anomaly detection1 APT1 ATT&CK1 attack lifecycle1 attack paths1 baselining1 behavior analytics2 brand monitoring1 campaign analysis1 capstone3 Capstone1 cognitive bias1 Collection1 Command and Control2 coverage1 Credential Access2 CTI6 CTI platforms1 cyber kill chain1 data sources1 Defender XDR1 Defense Evasion1 Detection as Code1 detection engineering4 DGA1 Diamond Model1 Discovery1 DNS1 DNS Tunneling1 documentation1 early warning1 EDR1 Elastic1 enrichment1 environmental knowledge1 EQL1 Execution3 Exfiltration1 external attack surface1 Fileless Malware1 Golden Ticket1 home lab1 hunt lifecycle1 hunt operations1 hunt planning2 hunt reporting1 hypothesis7 Impact1 incident response3 infrastructure1 Initial Access2 intrusion analysis1 investigation1 IOC1 Kerberos1 knowledge management1 KQL3 Lateral Movement1 Linux2 LOLBAS2 Malware Analysis1 maturity model1 Memory Forensics1 methodology6 Microsoft Sentinel1 Named Pipes2 Navigator1 Network1 operating model1 OSINT1 Persistence4 Playbook1 PowerShell2 prioritization1 Privilege Escalation1 Process Injection1 Process Trees1 procurement1 program building2 PsExec1 Pyramid of Pain1 ransomware1 Ransomware2 reconnaissance1 Registry2 resource development1 risk1 risk analysis1 security lab1 Sigma Rules1 SOC6 source evaluation1 Splunk1 Supply Chain1 Suricata1 Sysmon4 telemetry2 threat actors1 threat hunting17 threat intelligence9 threat landscape1 threat modeling1 TTP1 Windows1 Windows Event Logs1 Wireshark1 WMI2 YARA1 Zeek1