High-signal indicators for hunting
🔄 Pivot:📁 Threat Hunting
Malware
Ransomware
APT / Targeted
Nation-State
Trojan / Banker
Infostealer
Loader / Dropper
RAT
C2 / Beacon
Botnet
Cryptominer
Backdoor / Webshell
Spyware
Wiper
Phishing
Exploit / CVE
Scanner / Recon
DDoS
Tor / Dark Web
Proxy / VPN
Spam / Malspam
Crypto
Sanctions
Organized Crime
Fraud / Scam
Threat Hunting
Total Threat Hunting
1.7K
New (7d)
1.7K
Types
1
30-Day Trend
Type Mix
Top Threat Hunting Indicators Export
Threat Hunting Resources
↗ MITRE ATT&CK — TTP framework for hypotheses ↗ Sigma rules — Detection rule repo ↗ Atomic Red Team — TTP test library ↗ Elastic detection rules — SIEM detections ↗ Hunting maturity / HELK — Hunt platform reference ↗ LOLBAS — Living-off-the-land binariesAI Skills & Automation
🧠 Turn a hypothesis into detection logic
🧠 Generate Sigma/queries for a technique
🧠 Propose the next hunt from current findings
🔍 Pivot & investigate
🏹 Related theaters & actors
🧩 Advanced Capabilities
🔐 Detection & sharing
📜 Playbook — Threat Hunting response
- Direction — frame the requirement for Threat Hunting: what decision does this support, by when?
- Collection — triage the 1.7K Threat Hunting indicators, corroborate across sources, and action them; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports