Threat Hunting Mindset
Proactively find threats.
What Is Threat Hunting
Threat hunting is the proactive search for attackers who have evaded automated defenses. Instead of waiting for an alert, the hunter goes looking.
It assumes a breach may already exist and sets out to prove or disprove it.
Reactive vs Proactive
Traditional security is reactive: tools fire alerts and analysts respond. Hunting is proactive: humans seek threats no alert caught.
- Reactive: alert arrives, then investigate.
- Proactive: investigate, then maybe find a threat.
All lessons in this course
- Threat Hunting Mindset
- Hypothesis-Driven Hunting
- Using Logs and Telemetry
- MITRE ATT&CK Mapping