Threat hunting
Threat hunting is the proactive search for attackers who have already evaded automatic detections. It starts from “assume breach”: instead of waiting for the alert, the hunter forms hypotheses based on TTPs and searches for them in the telemetry.
Hunting vs automatic detection
Section titled “Hunting vs automatic detection”Detection (def-deteccion) rules that fire alerts on the KNOWNHunting proactive search for the UNKNOWN/evasive, guided by hypotheses -> what's found and is repeatable becomes a new detectionHunting models
Section titled “Hunting models”Hypothesis-based "if an APT uses technique X (ATT&CK T####), would we see Y in the logs?"IOC/TI-based search for indicators of a specific campaign (see cti-ioc)Anomaly-based baselining: the infrequent/odd (processes, connections, accounts)TTP-based hunt behavior (pyramid of pain): what hurts the attacker mostA hunt’s cycle
Section titled “A hunt’s cycle”1. HYPOTHESIS derived from TI/ATT&CK ("persistence via a suspicious scheduled task")2. DATA identify needed sources (Sysmon 1/11/13, 4698...) and their availability3. SEARCH queries in the SIEM/EDR; refine signal vs noise4. FINDING is there activity? -> IR (dfir) ; none? -> document and improve visibility5. OPERATIONALIZE turn the successful hunt into an automatic detectionExample hypotheses (with ATT&CK)
Section titled “Example hypotheses (with ATT&CK)”- T1053 scheduled tasks created outside change windows- T1055 injection: processes with remote threads / RWX memory (Sysmon 8/10)- T1021 lateral movement: anomalous SMB/WMI/PSRemoting use (see ad-lateral)- T1071 C2: periodic beaconing to odd domains (see mal-c2)- T1003 credential dumping: LSASS access (see ad-creds)Adversary emulation (validates hunt and detection)
Section titled “Adversary emulation (validates hunt and detection)”Atomic Red Team atomic tests per ATT&CK technique -> generate telemetry to hunt/validateCALDERA automated emulation of TTP chainsPurple team red + blue together: run a TTP and verify detection/hunt liveBlue Team / operation
Section titled “Blue Team / operation”- Prioritize hunts by relevant threat (CTI, see CTI fundamentals) and by ATT&CK coverage gaps.
- Every hunt yields a product: a new detection, better visibility, or a confirmed “clean”.
- Document hunts (hypothesis, queries, result) for repeatability and metrics.
- Requires good telemetry (Sysmon & telemetry) and retention (SIEM); no data, no hunt.
Real-world cases
Section titled “Real-world cases”- SolarWinds (2020): the evasive activity was found by hunting behavior, not by signature.
- Living-off-the-land campaigns (no malware) are only detected by hunting TTPs and anomalies.
- Purple teaming over ATT&CK is standard practice in mature organizations to close gaps.
Testing checklist
Section titled “Testing checklist”- Formulate hypotheses based on ATT&CK/CTI
- Verify the needed telemetry is available
- Run the search and refine signal vs noise
- Emulate the technique (Atomic Red Team/CALDERA) to validate
- Finding → IR (dfir); clean → improve visibility
- Operationalize the successful hunt as a detection
- Document and measure coverage (ATT&CK Navigator)