Threat Hunting Playbook
Threat Hunting Playbook
A Threat Hunting Playbook provides a structured, repeatable methodology for proactively detecting adversaries, uncovering hidden threats, and improving SOC visibility. This playbook is designed for Blue Teams, SOC analysts, DFIR responders, and threat hunters.
✔ Core Principles of Threat Hunting
- Proactive — hunting begins before alerts fire.
- Hypothesis-driven — every hunt starts with a question.
- Adversary-focused — based on attacker behavior, not signatures.
- Data‑centric — logs, telemetry, and artifacts drive conclusions.
- Iterative — hunts evolve as new evidence emerges.
✔ Threat Hunting Workflow
- Define the Hunt
- Create a hypothesis
- Map to MITRE ATT&CK techniques
- Identify required data sources
- Prepare the Environment
- Collect logs (EDR, Sysmon, Zeek, Suricata, Elastic)
- Validate visibility and coverage
- Ensure time synchronization
- Execute the Hunt
- Query data sources
- Pivot on suspicious events
- Correlate across hosts and networks
- Analyze Findings
- Identify anomalies
- Validate with threat intel
- Determine adversary behavior
- Document & Report
- Record hypothesis, steps, evidence
- Create detection rules
- Recommend mitigations
- Operationalize
- Convert findings into alerts
- Improve SIEM/EDR visibility
- Feed lessons back into future hunts
✔ MITRE ATT&CK Mapping
Every hunt should map to one or more ATT&CK techniques:
- Initial Access — phishing, drive‑by, valid accounts
- Execution — PowerShell, WMI, scripts
- Persistence — registry, scheduled tasks, services
- Privilege Escalation — token manipulation, UAC bypass
- Defense Evasion — obfuscation, disabling logs
- Credential Access — LSASS dumping, keylogging
- Lateral Movement — SMB, RDP, WinRM
- Command & Control — beaconing, encrypted channels
- Exfiltration — cloud storage, DNS tunneling
✔ Common Hunting Hypotheses
- “An attacker is using PowerShell for remote execution.”
- “A compromised host is beaconing to a C2 server.”
- “An adversary is moving laterally using SMB or RDP.”
- “Credentials were harvested using LSASS memory access.”
- “Suspicious persistence mechanisms were created.”
✔ Data Sources for Threat Hunting
- Endpoint — Sysmon, EDR, OSQuery, Velociraptor
- Network — Zeek, Suricata, PCAP, NetFlow
- Logs — Windows Event Logs, Linux audit logs
- Cloud — Azure AD, AWS CloudTrail, GCP logs
- Threat Intelligence — MISP, OpenCTI, Sigma
✔ Detection Engineering Output
Every hunt should produce:
- New SIEM queries
- New detection rules (Sigma, Suricata, YARA)
- Improved logging requirements
- Updated dashboards
- Documented procedures
✔ Example Hunt: Suspicious PowerShell Execution
Hypothesis
“An attacker is using PowerShell to execute malicious commands.”
Data Required
- Sysmon Event ID 1, 3, 7
- Windows Event Logs 4104
- EDR telemetry
Hunting Queries
- PowerShell with encoded commands
- PowerShell spawning unusual child processes
- Network connections initiated by PowerShell
Detection Output
- Sigma rule for suspicious PowerShell
- Elastic/Kibana visualization
- Alert for encoded command usage
✔ Final Thoughts
Threat hunting is a continuous, proactive discipline that strengthens your SOC, improves visibility, and uncovers threats that traditional detection misses. Use this playbook as a foundation for building repeatable, hypothesis-driven hunts that evolve with adversary behavior.
Comments
Post a Comment
Drop your thoughts below — no noise, no spam, just signal.