To embed a website or widget, add it to the properties panel.
To embed a website or widget, add it to the properties panel.
To embed a website or widget, add it to the properties panel.

Threat hunting ebooks

our research team actually uses

Threat hunting ebooks

our research team actually uses

Threat hunting ebooks

our research team actually uses

Three field guides for finding adversary infrastructure, writing the queries that surface it, and writing up what you find. Grab the ones you need.

3 resources

Built on HuntSQL and live infrastructure data

Free to download

EBOOK

Modern Threat Hunting

Ten practical steps for hunting on the Hunt.io platform, from finding a starting point to pivoting on certificates, SSH keys, C2 infrastructure, and open directories. Hands on, with a HuntSQL cheat sheet at the end.

Playbook

The Threat Hunter's Query Playbook

100 field proven HuntSQL queries for tracking malware, C2 servers, and phishing infrastructure. Grouped by use case across certificates, open directories, SSH, JARM, Nmap, and more, so you can adapt them to your own leads.

EBOOK

Threat Hunting Report Template

A structure for writing up a hunt so it is actually useful later: IOC documentation, ATT&CK technique mapping, and a clear place to record detection and intelligence gaps. Fill it in and hand it off.

Read the guide, then go hunt

Every example traces back to infrastructure we actually tracked, the certs, the fingerprints, the pivots between them. Sign up free and pull the same threads.

Read the guide, then go hunt

Every example traces back to infrastructure we actually tracked, the certs, the fingerprints, the pivots between them. Sign up free and pull the same threads.

Read the guide, then go hunt

Every example traces back to infrastructure we actually tracked, the certs, the fingerprints, the pivots between them. Sign up free and pull the same threads.

faq

Threat hunting, briefly explained

Threat hunting, briefly explained

Threat hunting, briefly explained

What is modern threat hunting?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

How is it different from traditional, IOC based detection?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

What is covered in the Modern Threat Hunting ebook?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

What is the Threat Hunter's Query Playbook?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

What is HuntSQL, and do I need to know SQL to use it?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

What is in the Threat Hunting Report Template?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

Who are these ebooks for, and are they free?

It is a proactive, hypothesis driven approach to threat hunting, built to catch activity that slips past traditional, alert based detection. It works from the assumption that an adversary may already have a foothold, and goes looking for traces of that activity rather than waiting for an alert to fire.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.