Three field guides for finding adversary infrastructure, writing the queries that surface it, and writing up what you find. Grab the ones you need.
3 resources
Built on HuntSQL and live infrastructure data
Free to download

EBOOK
Modern Threat Hunting
Ten practical steps for hunting on the Hunt.io platform, from finding a starting point to pivoting on certificates, SSH keys, C2 infrastructure, and open directories. Hands on, with a HuntSQL cheat sheet at the end.
Playbook
The Threat Hunter's Query Playbook
100 field proven HuntSQL queries for tracking malware, C2 servers, and phishing infrastructure. Grouped by use case across certificates, open directories, SSH, JARM, Nmap, and more, so you can adapt them to your own leads.
EBOOK
Threat Hunting Report Template
A structure for writing up a hunt so it is actually useful later: IOC documentation, ATT&CK technique mapping, and a clear place to record detection and intelligence gaps. Fill it in and hand it off.
faq
What is modern threat hunting?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
How is it different from traditional, IOC based detection?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
What is covered in the Modern Threat Hunting ebook?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
What is the Threat Hunter's Query Playbook?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
What is HuntSQL, and do I need to know SQL to use it?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
What is in the Threat Hunting Report Template?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.
Who are these ebooks for, and are they free?
It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.




