Hunt Before
the Alert Fires.
Five tools for hypothesis-driven threat hunting: build and track ATT&CK-mapped hunt hypotheses, pivot across infrastructure on a relationship graph, pull CVE- or campaign-tied query packs when you need to hunt fast, look up living-off-the-land binary abuse with detection queries ready to go, and work an ATT&CK technique end to end with an in-depth hunting guide.
TOOLS
HYPOS
Hypothesis Platform · ATT&CK Coverage Matrix
Structured hypothesis platform with a curated hunt database, tagged by ATT&CK technique, tactic, and data source.
LAUNCH HYPOS →
PIVEX
Pivot Graph · Infrastructure Relationship Mapping
Force-directed pivot graph for mapping relationships between IPs, domains, certificates, ASNs, and threat actors.
LAUNCH PIVEX →
TRACEPULSE
Threat Query Packs · CVE & Campaign-Tied
CVE and campaign-tied detection query packs, ready to deploy the moment a new CVE drops or a campaign is active.
LAUNCH TRACEPULSE →
LOLBIN-R
Living-Off-the-Land Binary Reference
Reference for LOLBAS abuse: legitimate use, attacker command syntax, detection queries, and defence guidance per binary, plus a category-driven hunting guide.
LAUNCH LOLBIN-R →
TTPHUNT
ATT&CK Hunting Guides · Concepts to Detection Queries
In-depth, practical MITRE ATT&CK hunting guides: prerequisite concepts, technique mechanics, real procedure examples, data sources, detection queries, false-positive guidance, and a working checklist. Starts with the full T1003 OS Credential Dumping family.
LAUNCH TTPHUNT →
ADPATH
From Foothold to Forest Admin.
Full Active Directory attack-path reference: 70 techniques across the intrusion lifecycle and 41 step-by-step attack chains, covering Kerberos, NTLM, ADCS (ESC1-16), ACL abuse, delegation, coercion, and hybrid Entra ID attacks.
LAUNCH ADPATH →