Huntbook by Predefender

Explore

The Huntbook

In every great pursuit, there lies a humble beginning. We all have to start somewhere. For us, the journey begins with setting ourselves a standard, a beacon to guide us. It is this commitment to excellence that will transform us from novices into vigilant guardians, from learners into adept threat hunters. Each step we take fortifies our resolve, forging our path toward mastery and making the cyber world a safer place for all.

– Roger C.B. Johnsen

Table of Contents

  • Basics

    An introduction to threat hunting as a discipline, covering the analyst mindset, how to move from alerts to hypotheses, and how to plan and start a hunting program.

  • Frameworks

    An overview of the analytical and adversary models used in threat hunting, including the Diamond Model, kill chains, MITRE ATT&CK, OODA Loop, Pyramid of Pain, and structured hunting frameworks like PEAK, TaHiTI and MaGMa.

  • Methodology

    An overview of the core threat hunting methodologies - anomaly-driven, hypothesis-driven and intelligence-driven - and how each approaches the search for adversary behaviour.

  • Deliveries

    A guide to what a threat hunt should produce, covering process documentation such as runbooks, playbooks and SOPs, situation reports, and how to document no-result hunts.