A field-focused curriculum built from the methodologies of CrowdStrike OverWatch, Red Canary, Elastic Security, Mandiant, and the PEAK/TaHiTI/SANS frameworks. Eleven chapters covering the full hunt lifecycle, including applied LOLBin abuse, identity/cloud-native, and container/Kubernetes hunting chapters.
No chapters match “”.
The shift from reactive to proactive. SOC maturity, adversary mindset, and the prerequisites for an effective hunt program.
The ABLE framework, ATT&CK-driven hypothesis creation, prioritization scoring, and converting threat intel reports into testable hunt plans.
The Cyber Kill Chain and how it relates to ATT&CK, plus Sqrrl Loop, PEAK, TaHiTI, SANS PAM model, and OTRF Playbook. When to use which framework and how to combine them.
Windows Event Logs, Sysmon, EDR, DNS, proxy, identity, and cloud telemetry. The visibility gap and ATT&CK data source coverage mapping.
Planning a hunt, writing hunting queries in KQL/SPL/Sigma, statistical analysis methods, pivot techniques, and iterating on findings.
Admiralty System, Diamond Model, Pyramid of Pain, confidence scoring, and false positive management.
The full PEAK lifecycle applied, hunt scoping templates, outcome classification, after-action reports, and KPI measurement.
Threat actor profiling, campaign-based hunting, ML-assisted methods, purple team validation, and building a hunt program.
Hunt for certutil, mshta, regsvr32, rundll32, and BITS abuse using behavioral hypotheses, KQL and Sigma queries, and the full ABLE workflow.
Hunt identity-centric attacks across Entra ID sign-in risk, AWS IAM role-assumption chains, and OAuth/SaaS token abuse. No process tree, no file system — just control-plane logs.
Hunt container escapes, privileged pods, and Kubernetes API abuse using ATT&CK for Containers, the K8s audit log, and Falco runtime rules.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
ATT&CK-driven hypothesis platform. Build and track hunt hypotheses using the ABLE framework.
KQL/Sigma/XQL detection query arsenal, organized by MITRE ATT&CK technique.
Pivot graph for threat investigations. Map relationships between IOCs, artifacts, and actors.
Threat query packs by campaign and CVE. Structured hunt packs ready to deploy.