How do you think computers are secured nowadays?
You might think of firewalls or antivirus solutions, such as Windows Defender. If you want to get fancy, consider a VPN like [insert name of VPN that keeps coming up every time I want to watch a YouTube video] or something more advanced, such as a YubiKey / fingerprint scanner to unlock your computer.
If you work for an enterprise, you might answer with “DDoS (Distributed Denial of Service) protection”, “an email gateway to filter malicious emails”, or “a costly Microsoft product”. Either way, all of these security solutions — and many others, such as IDS (Intrusion Detection Systems), EDR (Endpoint Detection Response), and WAF (Web Application Firewall) — are passive defenses that a security team will put in place to prevent an attacker from gaining access to their systems. You can think of them as walls designed to block entry and protect your precious treasure.
In cyber security, they are means of ensuring the confidentiality, integrity, and availability of data (the fabled CIA triad).

Walls are good. If I were a medieval king and my castle was being besieged, then I would want to be behind a few walls. However, I would also like to fight back and defend my castle! This is where threat hunting comes into play.
What is Threat Hunting?
Threat hunting is “the process of proactively and iteratively searching through networks to detect and isolate advanced threats that evade existing security solutions” (TechRepublic). It’s the blue team’s equivalent of actively defending their castle from an ongoing siege.
The “blue team” refers to the individuals tasked with defending an organisation, while the “red team” refers to the attackers.
A threat hunter will investigate a bad guy’s or girl’s (women can be criminals too) activity before there has been a warning of a potential threat from one of the many systems organisations use to protect themselves. They do this in numerous ways.:
- They could think like an attacker and try to emulate what they would do to breach an organisation, and then search for this activity.
- They could use analytics with machine learning or UEBA (User and Entity Behaviour Analytics) to calculate risky or uncommon behaviour patterns among users and then investigate these users.
- They could utilize threat intelligence derived from OSINT (Open Source Intelligence) or private intelligence feeds to search for a specific threat actor or IOC (Indicator of Compromise) within their environment.
Threat hunters merge red and blue team tactics (attack and defence) to better protect their organisation from threats that traditional security solutions miss. This is why they are so crucial to modern security teams in today’s cyber security landscape.
When to Use Threat Hunting
Not every organisation can afford or may benefit from a threat hunter or cyber threat intelligence (CTI) team. There are people/procedures/processes that an organisation must establish before it can even consider investing in a threat intelligence department.
- An organisation must have a basic IT setup in place (network infrastructure, an Active Directory environment, etc.) with traditional cyber security protections implemented to reach a base level of security (anti-virus, hardened servers, etc.).
- They need to ensure that they have accurate and timely log sources that cover their entire estate so that they can effectively monitor what is actually happening in their environment. This needs to be integrated into a platform that can manage all this data (e.g., a SIEM).
- Then they need to roll out EDR on all their endpoints to gain greater visibility and have some built-in protection if an attacker decides to attack/disable the organisation’s log sources.
- Finally, once all that is set up, they need an efficient way to manage their security by either outsourcing it to a managed service provider or creating their own in-house SOC (Security Operations Centre) that utilizes technologies like SOAR or XDR to respond efficiently to threats.
Then, and only then, can the organisation consider bolstering its active defences with a CTI team. This is one of the reasons good cyber security is so expensive!

This list of prerequisites is by no means exhaustive; there are also email security, physical security, and numerous other passive measures that need to be deployed as well.
Once an organisation reaches a decent level of cyber security maturity, it can then look at developing a CTI team to enhance its resilience to cyberattacks further.
This is where I, and this series, come in!
What This Series is About
In this series, I will teach you the fundamentals of becoming an effective threat hunter and, hopefully, develop your cyber security knowledge enough so that you can perform threat hunts in your own environment (whether it’s a home lab or an enterprise).
This series will first demonstrate how to create your own environment for threat hunting and utilize the free Digital Forensics and Incident Response tool, Velociraptor, to hunt for threats. Strap in and enjoy the ride!

Discover more in the Threat Hunting with Velociraptor series!



