A field-focused curriculum built from the methodologies of CrowdStrike OverWatch, Red Canary, Elastic Security, Mandiant, and the PEAK/TaHiTI/SANS frameworks. Nine chapters covering the full hunt lifecycle, including an applied LOLBin abuse hunting chapter.
The shift from reactive to proactive. SOC maturity, adversary mindset, and the prerequisites for an effective hunt program.
The ABLE framework, ATT&CK-driven hypothesis creation, prioritization scoring, and converting threat intel reports into testable hunt plans.
Sqrrl Loop, PEAK, TaHiTI, SANS PAM model, and OTRF Playbook. When to use which framework and how to combine them.
Windows Event Logs, Sysmon, EDR, DNS, proxy, identity, and cloud telemetry. The visibility gap and ATT&CK data source coverage mapping.
Planning a hunt, writing hunting queries in KQL/SPL/Sigma, statistical analysis methods, pivot techniques, and iterating on findings.
Admiralty System, Diamond Model, Pyramid of Pain, confidence scoring, and false positive management.
The full PEAK lifecycle applied, hunt scoping templates, outcome classification, after-action reports, and KPI measurement.
Threat actor profiling, campaign-based hunting, ML-assisted methods, purple team validation, and building a hunt program.
Hunt for certutil, mshta, regsvr32, rundll32, and BITS abuse using behavioral hypotheses, KQL and Sigma queries, and the full ABLE workflow.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
ATT&CK-driven hypothesis platform. Build and track hunt hypotheses using the ABLE framework.
KQL/Sigma/XQL detection query arsenal, organized by MITRE ATT&CK technique.
Pivot graph for threat investigations. Map relationships between IOCs, artifacts, and actors.
Threat query packs by campaign and CVE. Structured hunt packs ready to deploy.