What problem does it solve?
Threat-hunting helps you proactively identify adversary activity that has evaded existing detections, so you can confirm or rule out suspected compromise before it turns into an incident.
Core Features & Use Cases
- Hypothesis-driven hunting: Build a specific, testable, bounded hunt hypothesis tied to an ATT&CK technique and expected evidence rather than “browse the logs.”
- PEAK methodology execution: Prepare the hypothesis, execute using pivot/anomaly patterns, act on hits, and capture knowledge as artifacts (rules, documented results, or coverage gaps).
- High-yield hunt catalogs: Run targeted ideas across persistence, defense evasion, credential access, discovery, lateral movement, staging/exfiltration, plus cloud and identity-provider-specific scenarios.
Quick Start
Use the threat-hunting skill to run a PEAK-based hunt hypothesis for “T1059.001 (PowerShell) with -EncodedCommand launched by Office processes” within the last 30 days and produce a hunt report with findings, conclusion, and recommended detection or next steps.