<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Huntbook by Predefender</title><link>https://huntbook.predefender.com/</link><description>Recent updates from Huntbook by Predefender</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 22 Jun 2024 10:25:28 +0200</lastBuildDate><atom:link href="https://huntbook.predefender.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Understanding Data</title><link>https://huntbook.predefender.com/part-3/understanding-data/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-3/understanding-data/</guid><description>A threat hunter makes a living from understanding data. All kinds of data.
Understanding data is not the same as recognising a field name or knowing a query language. It means knowing where a record came from, what produced it, what each field represents, which transformations occurred, and what the source cannot tell you.
Only then can we use counts, patterns, rarity, relationships, and anomalies without turning convenient shapes into false conclusions.</description></item><item><title>Establishing a Timeline</title><link>https://huntbook.predefender.com/part-3/establishing-timeline/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-3/establishing-timeline/</guid><description>Over the years, I have trained many students to become SOC analysts and, eventually, threat hunters. Timelines are one of the concepts people tend to underestimate. They are often imagined as a straight line from point A to point B.
An investigation timeline is more demanding. It is a reconstruction built from observations that were recorded by different systems, at different moments, with different clocks and retention limits. It should help us understand what happened, what may have happened, and where the evidence is incomplete.</description></item><item><title>Intelligence Resources</title><link>https://huntbook.predefender.com/part-4/intelligence-resources/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/intelligence-resources/</guid><description>Threat intelligence is most useful when it adds context to an observation. A reputation result is not a verdict: infrastructure changes ownership, shared services host legitimate and malicious activity, and an indicator can outlive the campaign that created it.
!Treat every external query as disclosure Uploads expose the submitted artefact, but lookups may also reveal investigation targets or cause a provider to retrieve a submitted URL. Before querying a public service, check its sharing, retrieval, visibility, and retention behaviour.</description></item><item><title>T1105 – Ingress Tool Transfer</title><link>https://huntbook.predefender.com/part-4/mitre/t1105/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/mitre/t1105/</guid><description>iIllustrative queries Queries on this page are illustrative starting points. They demonstrate investigation logic, not production-ready detections. Table availability, field names, action types, parsing, retention, and normal behaviour vary by environment. Inspect raw records and validate every query against your local schema and telemetry before relying on the result.
Ingress Tool Transfer (T1105) describes adversaries transferring tools or other files from an external system into a compromised environment. The external source may be adversary-controlled infrastructure, a web or cloud service, or a command-and-control channel.</description></item><item><title>T1566 – Phishing</title><link>https://huntbook.predefender.com/part-4/mitre/t1566/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/mitre/t1566/</guid><description>iIllustrative queries Queries on this page are illustrative starting points. They demonstrate investigation logic, not production-ready detections. Table availability, field names, action types, parsing, retention, and normal behaviour vary by environment. Inspect raw records and validate every query against your local schema and telemetry before relying on the result.
Phishing (T1566) is delivery through a deceptive message or interaction. ATT&amp;amp;CK currently separates spearphishing attachment, spearphishing link, spearphishing via service, and spearphishing voice.</description></item><item><title>SIEM Query Languages</title><link>https://huntbook.predefender.com/part-4/siem-query-languages/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/siem-query-languages/</guid><description>iIllustrative queries Queries on this page are illustrative starting points. They demonstrate investigation logic, not production-ready detections. Table availability, field names, action types, parsing, retention, and normal behaviour vary by environment. Inspect raw records and validate every query against your local schema and telemetry before relying on the result.
Query syntax changes from platform to platform. The investigation method does not. I normally begin with a small time window and a narrow question, inspect raw records, confirm the schema, and only then aggregate or turn the query into a detection.</description></item><item><title>Windows Logons</title><link>https://huntbook.predefender.com/part-4/windows-logins/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/windows-logins/</guid><description>iIllustrative queries Queries on this page are illustrative starting points. They demonstrate investigation logic, not production-ready detections. Table availability, field names, action types, parsing, retention, and normal behaviour vary by environment. Inspect raw records and validate every query against your local schema and telemetry before relying on the result.
Windows logon events are evidence of authentication and session creation. They are not proof that a person was physically present, that the activity was interactive, or that the source address identifies the initiating endpoint.</description></item><item><title>MAC Addresses</title><link>https://huntbook.predefender.com/part-4/mac-addresses/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-4/mac-addresses/</guid><description>iIllustrative queries Queries on this page are illustrative starting points. They demonstrate investigation logic, not production-ready detections. Table availability, field names, action types, parsing, retention, and normal behaviour vary by environment. Inspect raw records and validate every query against your local schema and telemetry before relying on the result.
A MAC address can help connect an IP address to an interface, switch port, wireless association, or device record. It can also mislead you when observations from different times, broadcast domains, overlays, or network devices are treated as one identity.</description></item><item><title>Named Pipes</title><link>https://huntbook.predefender.com/part-5/named-pipes/</link><pubDate>Wed, 22 Jul 2026 16:10:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-5/named-pipes/</guid><description>Local and remote named-pipe telemetry for discovery, RPC, administration, and lateral movement.</description></item><item><title>Device-centric Pivoting in Defender XDR</title><link>https://huntbook.predefender.com/part-5/device-centric-pivoting/</link><pubDate>Wed, 22 Jul 2026 16:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-5/device-centric-pivoting/</guid><description>A repeatable workflow for expanding one device into network, process, file, identity, and alert evidence.</description></item><item><title>File Staging and User-writable Paths</title><link>https://huntbook.predefender.com/part-5/file-staging-user-writable-paths/</link><pubDate>Wed, 22 Jul 2026 16:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-5/file-staging-user-writable-paths/</guid><description>Hunting file origin, staging, extraction, execution, and cleanup in user-writable locations.</description></item><item><title>SMB, NetBIOS, and File Shares</title><link>https://huntbook.predefender.com/part-5/smb-netbios-file-shares/</link><pubDate>Wed, 22 Jul 2026 15:00:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-5/smb-netbios-file-shares/</guid><description>Hunting SMB, legacy NetBIOS traffic, administrative shares, remote execution, and file transfer.</description></item><item><title>FAQ</title><link>https://huntbook.predefender.com/about/faq/</link><pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/about/faq/</guid><description>Usage and licensing Is this content free? Yes. The PreDefender Threat Hunt Book is free to read online.
You may read it, save pages, bookmark pages, print pages, create a private copy for personal use, and share links to the material. You may also quote short excerpts when discussing or sharing the content, provided that attribution is included.
Please use this material for educational purposes. If you do, I appreciate a heads-up.</description></item><item><title>Analyst Mindset</title><link>https://huntbook.predefender.com/part-1/introduction/analystmindset/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/analystmindset/</guid><description>Author: Roger C.B. Johnsen
Introduction Threat hunting depends on how the analyst thinks. Tools matter. Telemetry matters. Detections matter. Frameworks matter. But none of them remove the need for human judgement. A threat hunter often works with incomplete evidence, noisy telemetry, unclear ownership, missing context and questions that do not have immediate answers. The work is rarely as clean as a lab example. Logs may be missing, alerts may only show part of the story, users may not remember what happened and system owners may not know what is normal.</description></item><item><title>Indicators</title><link>https://huntbook.predefender.com/part-1/introduction/indicators/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/indicators/</guid><description>Author: Roger C.B. Johnsen
Introduction Indicators are not answers. They are signals that help analysts decide what to investigate next. In SOC and threat hunting documentation, the word indicator is often used as if it only means IOC: IP addresses, domains, hashes, file names, registry keys and other concrete artefacts. Those indicators matter, but they are only one part of the picture. Threat hunting also depends on recognising attack-relevant activity and behaviour that differs from what is expected in the local environment.</description></item><item><title>Reports</title><link>https://huntbook.predefender.com/part-1/deliveries/reports/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/reports/</guid><description>Author: Roger C.B. Johnsen
Introduction A report is a structured way to preserve and communicate the outcome of security work. In threat hunting, reporting is often misunderstood. Some people think of a report as a long PDF written at the end of a major investigation. That can be true, but it is only one version of reporting.
A report may be a short case summary, a hunt report, a technical appendix, a detection recommendation, a baseline summary, an audit report, an executive briefing, a findings note or a formal incident report.</description></item><item><title>Baselines</title><link>https://huntbook.predefender.com/part-1/deliveries/baselines/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/baselines/</guid><description>Author: Roger C.B. Johnsen
Introduction A baseline is a documented understanding of expected behaviour within a defined scope. In threat hunting, baselines are important because many investigations start with a simple question: Is this normal here? That question is harder than it looks. Normal behaviour depends on the environment, the system, the user population, the business process, the time period and the available telemetry. What is normal for one organisation may be suspicious in another.</description></item><item><title>Detection Rules</title><link>https://huntbook.predefender.com/part-1/deliveries/detection-rules/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/detection-rules/</guid><description>Author: Roger C.B. Johnsen
Introduction A detection rule is an operationalised way to identify behaviour that should be reviewed. In threat hunting, a hunt may produce a finding, a baseline, a visibility gap or a better question. Sometimes it also produces something that should continue working after the hunt is finished. That output may become a detection rule.
A detection rule is not just a query. It is not just a condition in a SIEM, EDR or XDR platform.</description></item><item><title>Audits</title><link>https://huntbook.predefender.com/part-1/deliveries/audit/</link><pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/audit/</guid><description>Author: Roger C.B. Johnsen
Introduction An audit is a structured review of whether something still works as expected. In threat hunting and security operations, audits should not be understood only as compliance exercises. A threat hunter may perform or contribute to audits that check whether telemetry exists, whether detections still work, whether baselines are still valid, whether playbooks are followed, whether response actions are documented, or whether assumptions made during previous hunts still hold.</description></item><item><title>SOP</title><link>https://huntbook.predefender.com/part-1/deliveries/process-documentation/sop/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/process-documentation/sop/</guid><description>Author: Roger C.B. Johnsen
Introduction A Standard Operating Procedure, or SOP, defines the required way a recurring process should be performed. In security operations, some activities must be handled consistently regardless of who is on shift, which team is involved or which tool is being used. Incident escalation, evidence handling, case documentation, stakeholder notification, change approval and exception handling are examples of areas where the organisation needs a clear standard.</description></item><item><title>Playbook</title><link>https://huntbook.predefender.com/part-1/deliveries/process-documentation/playbook/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/process-documentation/playbook/</guid><description>Author: Roger C.B. Johnsen
Introduction A playbook is a scenario-based guide that helps a security team respond to a specific type of situation. In security operations, not every situation can be handled by a simple checklist. Some cases require judgement, branching decisions, escalation, evidence collection, containment choices and communication with several stakeholders. A playbook gives the team a structured way to approach a known scenario, such as phishing, ransomware, suspected account compromise, malware infection, data exfiltration or suspicious cloud activity.</description></item><item><title>Runbook</title><link>https://huntbook.predefender.com/part-1/deliveries/process-documentation/runbook/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/process-documentation/runbook/</guid><description>Author: Roger C.B. Johnsen
Introduction A runbook is a repeatable execution guide for a specific operational task. In security operations, many tasks need to be performed the same way regardless of who is on shift. Analysts may need to collect email headers, remove malicious messages from mailboxes, revoke user sessions, isolate an endpoint, export sign-in logs, block a domain, collect endpoint artefacts or run a specific hunt query.
These tasks are often part of a larger investigation or response.</description></item><item><title>SITREP</title><link>https://huntbook.predefender.com/part-1/deliveries/sitrep/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/sitrep/</guid><description>Author: Roger C.B. Johnsen
Introduction A SITREP, or Situation Report, is a structured operational update. It explains what is happening, what is known, what has been done and what should happen next. In threat hunting, SOC operations and incident management, communication is often just as important as technical analysis. A strong analyst may understand the situation, but if that understanding is not communicated clearly, the wider team may still be blind.</description></item><item><title>No Result Hunts</title><link>https://huntbook.predefender.com/part-1/deliveries/no-result-hunts/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/deliveries/no-result-hunts/</guid><description>Author: Roger C.B. Johnsen
Introduction A threat hunt can be valuable even when no threat is found That statement is important because many people instinctively measure threat hunting by whether it produces a confirmed incident, a detection, a compromised host or an interesting finding. That is understandable.
Security work is often judged by visible outcomes. But threat hunting does not only create value when it finds an adversary. A hunt can also validate assumptions, test telemetry, improve baselines, reveal visibility gaps, refine detection logic, strengthen documentation and teach the team more about the environment.</description></item><item><title>PEAK</title><link>https://huntbook.predefender.com/part-1/frameworks/threathunting/peak/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/threathunting/peak/</guid><description>Author: Roger C.B. Johnsen
Introduction PEAK is a threat hunting framework built around three activities: Prepare, Execute and Act with Knowledge.
The framework was developed by Splunk’s SURGe team and is intended to make threat hunting more repeatable, useful and connected to measurable security improvement. PEAK is not only about running hunts. It is about making sure the organisation prepares properly, executes with discipline and turns what it learns into something useful afterwards.</description></item><item><title>Hypothesis-Driven Hunting</title><link>https://huntbook.predefender.com/part-1/methodologies/hypothesis-driven/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/methodologies/hypothesis-driven/</guid><description>Author: Roger C.B. Johnsen
Introduction Hypothesis-driven hunting is a threat hunting approach where the hunter starts with a testable idea about possible adversary behaviour and then uses data to validate, weaken or reject it.
The hypothesis gives the hunt direction. It tells the hunter what behaviour to look for, which data sources may be relevant, what scope should be used and what kind of evidence would matter.
A weak hunt often starts with a vague question:</description></item><item><title>Diamond Model</title><link>https://huntbook.predefender.com/part-1/frameworks/diamondmodel/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/diamondmodel/</guid><description>Author: Roger C.B. Johnsen
Introduction The Diamond Model of Intrusion Analysis is a useful framework for structuring what we know, what we think we know, and what we still need to investigate during threat hunting and intrusion analysis.
The model was introduced by Sergio Caltagirone, Andrew Pendergast and Christopher Betz in 2013. It describes intrusion activity through four connected elements:
adversary infrastructure capability victim Those four elements form the “diamond”. For threat hunters, the value of the model is not that it magically identifies an attacker.</description></item><item><title>TaHiTI</title><link>https://huntbook.predefender.com/part-1/frameworks/threathunting/tahiti/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/threathunting/tahiti/</guid><description>Author: Roger C.B. Johnsen
Introduction TaHiTI is a threat hunting methodology for turning threat intelligence into focused hunting investigations.
TaHiTI stands for Targeted Hunting integrating Threat Intelligence. The methodology was created as a joint effort by several Dutch financial institutions through the Dutch financial institutes information sharing community, FI-ISAC. The goal was to create a shared understanding of threat hunting and a common approach to conducting threat hunting activities.
TaHiTI is targeted because the hunt should have a clear purpose.</description></item><item><title>Anomaly-Driven Hunting</title><link>https://huntbook.predefender.com/part-1/methodologies/anomaly-driven/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/methodologies/anomaly-driven/</guid><description>Author: Roger C.B. Johnsen
Introduction Anomaly-driven hunting is a threat hunting approach where the hunter looks for meaningful deviations from expected behaviour.
The basic idea is simple: malicious activity often creates behaviour that does not fit the normal pattern of an environment. A user logs in from an unusual location. A service account authenticates to systems it normally never touches. A workstation starts talking to infrastructure it has never contacted before.</description></item><item><title>Lockheed Martin Kill Chain</title><link>https://huntbook.predefender.com/part-1/frameworks/killchains-1/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/killchains-1/</guid><description>Author: Roger C.B. Johnsen
Introduction The Lockheed Martin Cyber Kill Chain is a framework for understanding cyber intrusions as a sequence of stages, from early preparation to the attacker’s final objective.
The model helps defenders reason about where an intrusion may be disrupted. If an organisation can detect or interrupt an attack at an earlier stage, the attacker may never reach command and control, lateral movement, data theft or other final objectives.</description></item><item><title>MaGMa</title><link>https://huntbook.predefender.com/part-1/frameworks/threathunting/magma/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/threathunting/magma/</guid><description>Author: Roger C.B. Johnsen
Introduction MaGMa is a use case management framework for organising, maintaining, measuring and improving security monitoring use cases.
MaGMa is not a threat hunting model in the same way that the Diamond Model, MITRE ATT&amp;amp;CK, the Kill Chain models or the OODA Loop are hunting and analysis models. It is better understood as a framework for managing the security monitoring and detection use cases that SOCs, hunters and detection engineers depend on.</description></item><item><title>Intelligence-Driven Hunting</title><link>https://huntbook.predefender.com/part-1/methodologies/intelligence-driven/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/methodologies/intelligence-driven/</guid><description>Author: Roger C.B. Johnsen
Introduction Intelligence-driven hunting is a threat hunting approach where threat intelligence is used to decide what to hunt, why it matters and how the investigation should be shaped.
The basic idea is simple: intelligence should not only be something the organisation reads. It should help the organisation decide what to investigate.
Threat intelligence may describe adversaries, campaigns, tools, infrastructure, vulnerabilities, targets, tactics, techniques and procedures. Some of that intelligence may be useful for detection.</description></item><item><title>Unified Kill Chain</title><link>https://huntbook.predefender.com/part-1/frameworks/killchains-2/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/killchains-2/</guid><description>Author: Roger C.B. Johnsen
Introduction The Unified Kill Chain (UKC) is a framework for describing cyber intrusions across the full lifecycle of an operation, from preparation and initial compromise to lateral movement, mission completion and impact.
The model, introduced by Paul Pols, combines ideas from Lockheed Martin’s Cyber Kill Chain and MITRE ATT&amp;amp;CK. The result is a broader framework that helps defenders reason about both attack progression and attacker behaviour.</description></item><item><title>MITRE ATT&amp;CK</title><link>https://huntbook.predefender.com/part-1/frameworks/mitreattack/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/mitreattack/</guid><description>Author: Roger C.B. Johnsen
Introduction MITRE ATT&amp;amp;CK is a knowledge base of adversary tactics, techniques and procedures based on observed real-world behaviour.
For threat hunters, the value of ATT&amp;amp;CK is not that it tells us what happened. It does not. The value is that it gives us a common language for describing adversary behaviour in a precise and repeatable way.
That distinction is important. A vague statement such as this may be technically true, but it is not very useful:</description></item><item><title>OODA Loop</title><link>https://huntbook.predefender.com/part-1/frameworks/ooda/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/ooda/</guid><description>Author: Roger C.B. Johnsen
Introduction The OODA Loop is a decision-making framework built around four activities: Observe, Orient, Decide and Act.
The model is commonly associated with United States Air Force Colonel John Boyd and was originally developed in a military context. It is often used to explain how people and organisations make decisions in competitive, uncertain and fast-moving environments.
Personally, I think the OODA Loop is one of those models that is far more useful than its original context suggests.</description></item><item><title>Pyramid of Pain</title><link>https://huntbook.predefender.com/part-1/frameworks/pyramidofpain/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/frameworks/pyramidofpain/</guid><description>Author: Roger C.B. Johnsen
Introduction The Pyramid of Pain is a model for thinking about how much difficulty we create for an adversary when we detect, block or disrupt different types of indicators.
The model was created by David J. Bianco and is widely used in threat hunting, incident response, detection engineering and threat intelligence. It is simple, but it teaches an important lesson: not all indicators have the same defensive value.</description></item><item><title>Definition</title><link>https://huntbook.predefender.com/part-1/introduction/definition/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/definition/</guid><description>Author: Roger C.B. Johnsen
Introduction Ask ten people what threat hunting is, and you will probably get ten slightly different answers. One SOC may mean IOC searches. Another may mean detection engineering based on threat intelligence. A vendor may describe it as a platform capability. In newer AI-driven SOC discussions, someone may even claim that threat hunting can be done automatically by an AI agent. Some of those perspectives are useful.</description></item><item><title>Hierarchy of Needs</title><link>https://huntbook.predefender.com/part-1/introduction/hierarchy-of-needs/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/hierarchy-of-needs/</guid><description>Author: Roger C.B. Johnsen
Introduction Threat hunting does not start with a clever hypothesis. It starts with the boring layers underneath it: assets, telemetry, detection, triage and incident response capability.
Many organisations want threat hunting before they have the foundations needed to support it. They want proactive investigation, but they do not know what they own. They want behavioural analysis, but they do not collect the right telemetry. They want hunters to find what detections miss, but the SOC is still struggling to understand ordinary alerts.</description></item><item><title>The Threat Hunter Persona</title><link>https://huntbook.predefender.com/part-1/introduction/the-threathunter-persona/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/the-threathunter-persona/</guid><description>Author: Roger C.B. Johnsen
Introduction A threat hunter is not a superhero profile. It is not a job title that automatically appears after a few years in a SOC. It is a combination of curiosity, technical range, analytical discipline and enough operational experience to know when the data does not support the story.
Many threat hunters come from SOC, incident response, digital forensics, threat intelligence, penetration testing, systems administration or development.</description></item><item><title>Context Before Conclusion</title><link>https://huntbook.predefender.com/part-1/introduction/context-before-conclusion/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/context-before-conclusion/</guid><description>Author: Roger C.B. Johnsen:
Introduction Threat hunts rarely start with complete evidence. Often, it is just a fragment: an IOC from a report, a suspicious process, an unusual login, a file found on disk, a SOC escalation, a red team observation, or a weak anomaly in the data. But a starting point is not a finding. It is the first question. The value of threat hunting lies in building enough context around that fragment to understand what it represents, whether it matters, and which hypothesis it supports or weakens.</description></item><item><title>From Alerts to Hypotheses</title><link>https://huntbook.predefender.com/part-1/introduction/from-alerts-to-hypothesis/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/from-alerts-to-hypothesis/</guid><description>Author: Roger C.B. Johnsen
Introduction Threat hunters do not all come from the SOC. Some come from incident response, digital forensics, threat intelligence, systems administration, development, network engineering, penetration testing, military environments or self-directed technical work.
This chapter focuses on one common and important path: the transition from SOC alert handling to hypothesis-driven threat hunting. It is not the only path into hunting, but it is a useful one to study because alerts teach analysts something valuable about evidence, telemetry, detection limits and operational reality.</description></item><item><title>Creating Hypotheses</title><link>https://huntbook.predefender.com/part-1/introduction/creating-hypothesis/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/creating-hypothesis/</guid><description>Author: Roger C.B. Johnsen
Introduction The previous chapters introduced hypotheses as part of threat hunting methodology. This chapter goes deeper. It focuses on how to create hypotheses that are specific, testable, relevant and useful enough to drive an actual hunt.
Threat hunting relies on more than intuition and experience. Those things matter, but they are not enough. A hunt needs a structured question. It needs a reason. It needs observable behaviour.</description></item><item><title>Planning a Threat Hunt</title><link>https://huntbook.predefender.com/part-1/introduction/planning-a-threat-hunt/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/planning-a-threat-hunt/</guid><description>Author: Roger C.B. Johnsen
Introduction The previous chapter described how to start and grow a threat hunting programme. This chapter moves one level down: how to plan a single hunt.
A threat hunting programme gives you the capability. A hunt plan turns that capability into a specific investigation.
That distinction matters.
A hunt plan is not a project plan. It is not a long document written to satisfy process requirements. It is the bridge between a hypothesis and an investigation.</description></item><item><title>How to Start a Threat Hunting Program</title><link>https://huntbook.predefender.com/part-1/introduction/how-to-start-a-threat-hunting-program/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/how-to-start-a-threat-hunting-program/</guid><description>Author: Roger C.B. Johnsen
Introduction One question I often hear when discussing threat hunting is simple: how do we start a threat hunting programme? The answer depends on the organisation. Some companies already have a mature SOC, good telemetry, clear incident response processes and people who understand the environment. Others are still mostly reactive, with uneven logging, unclear ownership and detections that are difficult to trust. Both may want threat hunting, but they cannot start from the same place.</description></item><item><title>When to Engage Threat Hunters</title><link>https://huntbook.predefender.com/part-1/introduction/when-to-engage-threat-hunters/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://huntbook.predefender.com/part-1/introduction/when-to-engage-threat-hunters/</guid><description>Author: Roger C.B. Johnsen
Introduction Threat hunters should be engaged when the organisation has a question that cannot be answered by alerts alone.
That question may appear before an incident, during SOC triage, during incident response, after a major incident, or when new threat intelligence raises concern about activity that existing detections may not cover.
Threat hunting is not a replacement for alerting, SOC triage, incident response or digital forensics. It is a complementary capability.</description></item><item><title>Hunter to Detection</title><link>https://huntbook.predefender.com/part-6/hunter-to-detection/</link><pubDate>Sun, 28 Jun 2026 12:51:29 +0200</pubDate><guid>https://huntbook.predefender.com/part-6/hunter-to-detection/</guid><description>Author: Roger C.B. Johnsen
Introduction There are findings in threat hunting that most organisations treat as the end of the investigation. A suspicious process. An unusual command line. A strange authentication pattern. A tool found on disk. The list goes on. The case gets scoped, the immediate risk is handled and everyone moves on.
But for a threat hunter, a finding should not only answer what happened. It should create a better question: how would we find this again?</description></item><item><title>PowerShell Hunting</title><link>https://huntbook.predefender.com/part-5/powershell/</link><pubDate>Fri, 21 Mar 2025 21:22:12 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/powershell/</guid><description>PowerShell telemetry, suspicious patterns, and practical pivots.</description></item><item><title>Microsoft Defender XDR Hunting Tables</title><link>https://huntbook.predefender.com/part-5/kusto-sentinel-tables/</link><pubDate>Fri, 21 Mar 2025 20:10:35 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/kusto-sentinel-tables/</guid><description>A practical map of Defender XDR advanced hunting tables and pivot keys.</description></item><item><title>Sysmon Hunting</title><link>https://huntbook.predefender.com/part-5/sysmon/</link><pubDate>Fri, 21 Mar 2025 20:10:23 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/sysmon/</guid><description>Sysmon event IDs, correlation fields, and high-value hunting questions.</description></item><item><title>Windows Registry Hunting</title><link>https://huntbook.predefender.com/part-5/windows-registry/</link><pubDate>Fri, 21 Mar 2025 20:10:17 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/windows-registry/</guid><description>High-value Windows Registry paths, artefacts, caveats, and pivots.</description></item><item><title>IP Protocol Numbers</title><link>https://huntbook.predefender.com/part-5/ip-protocol-numbers/</link><pubDate>Sun, 16 Mar 2025 11:29:22 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/ip-protocol-numbers/</guid><description>A hunting-oriented reference for IP protocol and IPv6 Next Header values.</description></item><item><title>Network Services and Ports</title><link>https://huntbook.predefender.com/part-5/network-services/</link><pubDate>Sun, 16 Mar 2025 10:32:41 +0100</pubDate><guid>https://huntbook.predefender.com/part-5/network-services/</guid><description>Common ports, useful pivots, and the context needed to hunt network services.</description></item><item><title>Setting Up a Complete Lab</title><link>https://huntbook.predefender.com/part-2/setting-up-a-complete-lab/</link><pubDate>Fri, 13 Sep 2024 13:05:47 +0200</pubDate><guid>https://huntbook.predefender.com/part-2/setting-up-a-complete-lab/</guid><description>Author: Roger C.B. Johnsen
Introduction In the chapter &amp;ldquo;Setting Up a Basic Lab ,&amp;rdquo; we covered how to install a simple Threat Hunting lab using OpenSearch on Alma Linux in VirtualBox. Now, in this chapter, we&amp;rsquo;ll focus on building a more comprehensive lab environment with additional tools based on the system described in the previous chapter. Our main goal here is to automate the installation process so the environment can be easily set up and torn down as needed.</description></item><item><title>Ingesting Windows Logs</title><link>https://huntbook.predefender.com/part-2/ingesting-windows-logs/</link><pubDate>Mon, 05 Aug 2024 20:01:02 +0200</pubDate><guid>https://huntbook.predefender.com/part-2/ingesting-windows-logs/</guid><description>Author: Roger C.B. Johnsen
Introduction Windows logs are vital for threat hunters because they provide critical insights into system activities, security incidents, and potential vulnerabilities. These logs capture detailed information about user actions, application behaviours, and system events, helping to identify suspicious activities and trace the steps of potential threats. By analysing Windows Event Logs, threat hunters can detect anomalies, investigate security breaches, and ensure robust system defences.
This chapter offers a generic guide for ingesting Windows .</description></item><item><title>Ingesting with Filebeat</title><link>https://huntbook.predefender.com/part-2/ingesting-with-filebeat/</link><pubDate>Mon, 05 Aug 2024 20:01:02 +0200</pubDate><guid>https://huntbook.predefender.com/part-2/ingesting-with-filebeat/</guid><description>Author: Roger C.B. Johnsen
Introduction Filebeat is a lightweight log shipper designed to forward and centralise various types of logs. As part of the Elastic Stack (ELK Stack), Filebeat is specifically tailored to collect logs and send them to Elasticsearch, Logstash, or third-party services for analysis and visualisation. When we refer to Filebeat as a &amp;ldquo;shipper,&amp;rdquo; we mean it&amp;rsquo;s a tool that takes your logs and sends them to a SIEM, to put it simply.</description></item><item><title>API Bulk Ingesting Logs</title><link>https://huntbook.predefender.com/part-2/api-bulk-ingesting-logs/</link><pubDate>Sun, 04 Aug 2024 09:48:00 +0200</pubDate><guid>https://huntbook.predefender.com/part-2/api-bulk-ingesting-logs/</guid><description>Author: Roger C.B. Johnsen
Introduction In this section, we will learn how to import logs into OpenSearch, a process known as log ingestion. There are many methods for ingesting logs into OpenSearch, but we will focus on a script that uses the Python API. The script will read an Ndjson log file of your choice and ingest the data into OpenSearch. In this chapter, we will work within the Alma Linux instance, executing the Python script locally.</description></item><item><title>Setting Up a Basic Lab</title><link>https://huntbook.predefender.com/part-2/setting-up-a-basic-lab/</link><pubDate>Sat, 03 Aug 2024 14:25:28 +0200</pubDate><guid>https://huntbook.predefender.com/part-2/setting-up-a-basic-lab/</guid><description>Author: Roger C.B. Johnsen
Introduction Being a successful threat hunter means having access to the right tools. One such tool is a system for log querying, which is crucial for detecting and analysing potential security threats. There are many systems out there that fit the bill, to just name a few:
Elastic QRadar Splunk OSSIM WAZUH Datadog And there are surely many other alternatives too. In this chapter, we are going to set up a tool called OpenSearch .</description></item><item><title>About</title><link>https://huntbook.predefender.com/about/author/</link><pubDate>Sat, 22 Jun 2024 13:51:13 +0200</pubDate><guid>https://huntbook.predefender.com/about/author/</guid><description>Roger Johnsen I work as a Lead Security Architect with a strong focus on security operations, threat hunting, threat-informed defence, detection engineering, and practical blue team capability building.
My background sits somewhere between security operations, software development, analyst enablement, and hands-on investigation work. I have worked as a SOC analyst, threat hunter, penetration tester, developer, consultant, trainer, and security leader. That mix has shaped how I think about security: good security work needs structure, technical depth, operational realism, and people who understand why they are doing what they are doing.</description></item><item><title>Contact</title><link>https://huntbook.predefender.com/about/contact/</link><pubDate>Sat, 22 Jun 2024 10:30:06 +0200</pubDate><guid>https://huntbook.predefender.com/about/contact/</guid><description>The best way to reach me is by e-mail or LinkedIn.
For professional inquiries, feedback, corrections, or questions related to the Huntbook, please use e-mail. LinkedIn is also fine if you prefer a quick introduction or professional message.
Please include the actual question or context in your first message. A short, clear message is much easier to respond to than just &amp;ldquo;hi&amp;rdquo;.
Contact details Media Username / link E-mail contact@predefender.com LinkedIn Public profile BlueSky rjohnsen.</description></item></channel></rss>