All Modules THREAT HUNTING

Threat Hunting · Complete Guide

A field-focused curriculum built from the methodologies of CrowdStrike OverWatch, Red Canary, Elastic Security, Mandiant, and the PEAK/TaHiTI/SANS frameworks. Eleven chapters covering the full hunt lifecycle, including applied LOLBin abuse, identity/cloud-native, and container/Kubernetes hunting chapters.

11 CHAPTERS
~14 HRS CONTENT
BEGINNER → ADVANCED SKILL RANGE
JUN 2026 LAST UPDATED
MODULE PROGRESS 0 / 11 chapters complete
hypothesis-driven PEAK TaHiTI ATT&CK KQL Sigma evidence scoring cloud & identity containers

ALL CHAPTERS

/
01
BEGINNER 25 min

Threat Hunting Foundations

The shift from reactive to proactive. SOC maturity, adversary mindset, and the prerequisites for an effective hunt program.

foundations SOC mindset
02
BEGINNER 30 min

Hypothesis Generation

The ABLE framework, ATT&CK-driven hypothesis creation, prioritization scoring, and converting threat intel reports into testable hunt plans.

ABLE ATT&CK intel
03
INTERMEDIATE 40 min

Hunting Frameworks

The Cyber Kill Chain and how it relates to ATT&CK, plus Sqrrl Loop, PEAK, TaHiTI, SANS PAM model, and OTRF Playbook. When to use which framework and how to combine them.

Kill Chain PEAK TaHiTI
04
INTERMEDIATE 30 min

Data Sources and Telemetry

Windows Event Logs, Sysmon, EDR, DNS, proxy, identity, and cloud telemetry. The visibility gap and ATT&CK data source coverage mapping.

logs EDR Sysmon
05
INTERMEDIATE 35 min

Hunt Execution

Planning a hunt, writing hunting queries in KQL/SPL/Sigma, statistical analysis methods, pivot techniques, and iterating on findings.

KQL queries pivoting
06
INTERMEDIATE 25 min

Evidence Quality and Scoring

Admiralty System, Diamond Model, Pyramid of Pain, confidence scoring, and false positive management.

Admiralty Diamond Pyramid
07
ADVANCED 30 min

Hunt Lifecycle and Documentation

The full PEAK lifecycle applied, hunt scoping templates, outcome classification, after-action reports, and KPI measurement.

PEAK reporting KPIs
08
ADVANCED 40 min

Advanced Topics

Threat actor profiling, campaign-based hunting, ML-assisted methods, purple team validation, and building a hunt program.

ML purple team AI
09
ADVANCED 40 min

Hunting LOLBin Abuse

Hunt for certutil, mshta, regsvr32, rundll32, and BITS abuse using behavioral hypotheses, KQL and Sigma queries, and the full ABLE workflow.

LOLBins T1218 detection
10
ADVANCED 40 min

Identity and Cloud-Native Hunting

Hunt identity-centric attacks across Entra ID sign-in risk, AWS IAM role-assumption chains, and OAuth/SaaS token abuse. No process tree, no file system — just control-plane logs.

Entra ID AWS IAM OAuth
11
ADVANCED 40 min

Container and Kubernetes Hunting

Hunt container escapes, privileged pods, and Kubernetes API abuse using ATT&CK for Containers, the K8s audit log, and Falco runtime rules.

Kubernetes Falco T1611

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Basic Windows OS concepts: processes, registry, file system structure
  • Familiarity with log concepts: event IDs, timestamps, field structure
  • Some exposure to a SIEM or query language (KQL, SPL, or similar)
  • General understanding of the cyber kill chain or ATT&CK framework

WHAT YOU WILL KNOW AFTER

  • The full threat hunting lifecycle from scoping to after-action reporting
  • How to write testable hypotheses using ABLE and ATT&CK data sources
  • PEAK, TaHiTI, and Sqrrl Loop: when and how to apply each
  • Hunting query writing in KQL, SPL, and Sigma
  • Evidence scoring using Admiralty, Diamond Model, and Pyramid of Pain
  • How to build and measure a hunt program using KPIs
  • How to hunt identity-centric attacks (Entra ID, AWS IAM, OAuth) and container/Kubernetes environments

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.