Work / Collection

Threat hunts

Hunt reports from cyber range exercises. Each one starts from a hypothesis and follows the evidence through endpoint telemetry until the hypothesis is proved or dropped.

Reports
Data
EDR and SIEM telemetry
Framework
MITRE ATT&CK

Reports

    How each report is built

    • Scenario and hypothesis: what triggered the hunt and what I expected to find.
    • Data sources: which tables and logs were available, and which were missing.
    • Findings by stage: the query, what it returned, and the ATT&CK technique it maps to.
    • Analyst assessment: timeline, likely intent, and how confident I am.
    • Recommendations: detections and mitigations that would catch it earlier next time.

    All activity in these reports took place in controlled cyber range simulations.