Skip to content

Threat hunting

Threat hunting is the proactive search for attackers who have already evaded automatic detections. It starts from “assume breach”: instead of waiting for the alert, the hunter forms hypotheses based on TTPs and searches for them in the telemetry.

Detection (def-deteccion) rules that fire alerts on the KNOWN
Hunting proactive search for the UNKNOWN/evasive, guided by hypotheses
-> what's found and is repeatable becomes a new detection
Hypothesis-based "if an APT uses technique X (ATT&CK T####), would we see Y in the logs?"
IOC/TI-based search for indicators of a specific campaign (see cti-ioc)
Anomaly-based baselining: the infrequent/odd (processes, connections, accounts)
TTP-based hunt behavior (pyramid of pain): what hurts the attacker most
1. HYPOTHESIS derived from TI/ATT&CK ("persistence via a suspicious scheduled task")
2. DATA identify needed sources (Sysmon 1/11/13, 4698...) and their availability
3. SEARCH queries in the SIEM/EDR; refine signal vs noise
4. FINDING is there activity? -> IR (dfir) ; none? -> document and improve visibility
5. OPERATIONALIZE turn the successful hunt into an automatic detection
- T1053 scheduled tasks created outside change windows
- T1055 injection: processes with remote threads / RWX memory (Sysmon 8/10)
- T1021 lateral movement: anomalous SMB/WMI/PSRemoting use (see ad-lateral)
- T1071 C2: periodic beaconing to odd domains (see mal-c2)
- T1003 credential dumping: LSASS access (see ad-creds)

Adversary emulation (validates hunt and detection)

Section titled “Adversary emulation (validates hunt and detection)”
Atomic Red Team atomic tests per ATT&CK technique -> generate telemetry to hunt/validate
CALDERA automated emulation of TTP chains
Purple team red + blue together: run a TTP and verify detection/hunt live
  • Prioritize hunts by relevant threat (CTI, see CTI fundamentals) and by ATT&CK coverage gaps.
  • Every hunt yields a product: a new detection, better visibility, or a confirmed “clean”.
  • Document hunts (hypothesis, queries, result) for repeatability and metrics.
  • Requires good telemetry (Sysmon & telemetry) and retention (SIEM); no data, no hunt.
  • SolarWinds (2020): the evasive activity was found by hunting behavior, not by signature.
  • Living-off-the-land campaigns (no malware) are only detected by hunting TTPs and anomalies.
  • Purple teaming over ATT&CK is standard practice in mature organizations to close gaps.
  • Formulate hypotheses based on ATT&CK/CTI
  • Verify the needed telemetry is available
  • Run the search and refine signal vs noise
  • Emulate the technique (Atomic Red Team/CALDERA) to validate
  • Finding → IR (dfir); clean → improve visibility
  • Operationalize the successful hunt as a detection
  • Document and measure coverage (ATT&CK Navigator)