Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

What is Threat Hunting?

Posted on March 15, 2018 By Michael Kavka No Comments on What is Threat Hunting?

Threat Hunting, yes another set of buzzwords. The world of Information Security is a smorgasbord of buzzwords. Still, threat hunting.  It sound glamorous, worthwhile, fun and interesting. The question is, just what is it?

I admit it, I am taken in by the idea of Threat Hunting. Feels like something important (which it is) and cool (depends on your point of view). I want to be a good threat hunter, and so do many people both blue and red teamers alike. The problem is, that Threat Hunting is a huge umbrella area. It is non-specific. Earlier this week the topic of what is threat hunting was asked by Dr. Anton Chuvakin on twitter.

What are the most abysmally fake examples of totally NOT threat hunting that vendor(s) called “threat hunting”? #question

— Dr. Anton Chuvakin (@anton_chuvakin) March 10, 2018

 

The thread is a good look at how people view threat hunting, and what it is or is not. Dr. Chuvakin responded with this:

Well, this is how I am planning to phase it 🙂 pic.twitter.com/sH6QTijT8V

— Dr. Anton Chuvakin (@anton_chuvakin) March 13, 2018

 

There are some flaws with this thinking, and it all comes down to how you define threat hunting. Let us move away from information security for a second, remove the word threat and look at wha they key word is, Hunting.

You want to get some fresh venison, and a set of antlers on your wall. Deer hunting season is here. So how does one go about hunting a deer? First you have to get to the woods with some sort of weapon (gun, bow, spear for those really wanting a challenge).  Next to have to find the deer. Track it. How do you do that? Find footprints, use some sort of sound or smell, anything to track down the deer. You become a detective, and use deception. Finally you have to actually take the shot and hope it is good for the kill. Three main phases of hunting: Location, Deception/Detection, Kill shot. Is it not hunting if you have a dog that helps automate the detective/deception phase. That dog makes it easier to find the deer.

Now let us look at how that relates to Threat Hunting in the world of infosec. Phase 1: Location. You can threat hunt in your own network (which most of us do knowingly or unknowingly), out in the Internet, on the Dark Web. You can hunt for the vulnerabilities, the compromises, zero day attacks. You can hunt for The actors, malware, lateral movement. What is the location, the area you are hunting in? Phase 2 is where you do your detective work. This can include honeypots, honeynets, deception technology, going through logs manually or using automation. To say going through large amounts of data, not using tools, or anything else that limits how you can find the threat(s) is limiting your success. In fact, Threat Detection (Incident Detection) is the first two phases of threat hunting. They are a subset of threat hunting. The kill shot is the only difference. That kill shot in our world can be plugging the hole, removing the malware, blocking a C2 IP address, anything that kills(mitigates) the immediate threat that you have found.

This is true threat hunting. It is not about the tools, any tool can be used. It is about the result. Did you find the threat and remove or mitigate it? Threat hunting is a process, and one that many things can fall under. It can only be defined in the broadest terms and then whittled down to specific areas. Trying to shrink those broadest terms and limit what can be used does nothing but hurt the hunt and puts us at a bigger disadvantage to beating the black hats we are after.

Rants, Security Tags:Deception Technology, Threat Hunting

Post navigation

Previous Post: The case for proper information or WHY CAN’T I UPGRADE THIS?
Next Post: Incident or Typo?

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • ISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st) September 21, 2026
  • Living Off the Land: A Valid Signature Is Not a Business Reason September 21, 2026 info@threathunter.ai (James McMurry)
  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • ISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st) September 21, 2026
  • Living Off the Land: A Valid Signature Is Not a Business Reason September 21, 2026 info@threathunter.ai (James McMurry)
  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.