Explore
The Huntbook
In every great pursuit, there lies a humble beginning. We all have to start somewhere. For us, the journey begins with setting ourselves a standard, a beacon to guide us. It is this commitment to excellence that will transform us from novices into vigilant guardians, from learners into adept threat hunters. Each step we take fortifies our resolve, forging our path toward mastery and making the cyber world a safer place for all.
– Roger C.B. Johnsen
Table of Contents
- Basics
An introduction to threat hunting as a discipline, covering the analyst mindset, how to move from alerts to hypotheses, and how to plan and start a hunting program.
- Frameworks
An overview of the analytical and adversary models used in threat hunting, including the Diamond Model, kill chains, MITRE ATT&CK, OODA Loop, Pyramid of Pain, and structured hunting frameworks like PEAK, TaHiTI and MaGMa.
- Methodology
An overview of the core threat hunting methodologies - anomaly-driven, hypothesis-driven and intelligence-driven - and how each approaches the search for adversary behaviour.
- Deliveries
A guide to what a threat hunt should produce, covering process documentation such as runbooks, playbooks and SOPs, situation reports, and how to document no-result hunts.