Work / Collection
Threat hunts
Hunt reports from cyber range exercises. Each one starts from a hypothesis and follows the evidence through endpoint telemetry until the hypothesis is proved or dropped.
- Reports
- Data
- EDR and SIEM telemetry
- Framework
- MITRE ATT&CK
Reports
How each report is built
- Scenario and hypothesis: what triggered the hunt and what I expected to find.
- Data sources: which tables and logs were available, and which were missing.
- Findings by stage: the query, what it returned, and the ATT&CK technique it maps to.
- Analyst assessment: timeline, likely intent, and how confident I am.
- Recommendations: detections and mitigations that would catch it earlier next time.
All activity in these reports took place in controlled cyber range simulations.