Threat Hunting for Beginners (Defence)
Threat hunting is a defender practice: you form a hypothesis about how an adversary might hide in your environment, query the telemetry you already collect, document findings, and either open an incident, write a new detection, or close the lead with evidence — not wait forever for a perfect SIEM alert.
Friends! Waiting only for SIEM alerts = reactive. Hunt = "what if the attacker is already here?" Hypothesis → query → notes → detection or close. Beginner-friendly, defence only. Do not hunt on another company's systems — own lab / employer authorisation.
मित्रांनो! SIEM alert wait = reactive. Hunt = "काय असेल जर attacker already आहेत?" Hypothesis → query → notes → detection किंवा close. Beginner-friendly, defence only. दुसऱ्या company च्या systems वर hunt नको — own lab / employer authorisation.
मित्रों! SIEM alert wait = reactive. Hunt = "क्या होगा अगर attacker already हैं?" Hypothesis → query → notes → detection या close. Beginner-friendly, defence only. दूसरी company के systems पर hunt नहीं — own lab / employer authorisation.
Quick answer
Beginner threat hunt — vertical loop:
- Pick a hypothesis tied to your real data (example: “rare country VPN success then new inbox rule”).
- Confirm you have the logs (identity, EDR, DNS, email, cloud audit).
- Query a focused time window; exclude known-good consciously.
- Pivot on user / host / IP — build a short timeline.
- Decide: incident, detection gap, or benign with proof.
- Write notes a teammate can re-run next week.
- Schedule the next hunt; do not “hunt forever” without tickets.
Tiny mental model:
Hypothesis → Telemetry → Query → Findings → IR or detection or close
No telemetry = sightseeing
No notes = tribal knowledge that quits with you
What do I need before this guide?
- SIEM basics: What is SIEM / how SOC uses it.
- Optional detections: MITRE ATT&CK + Sigma.
- Optional endpoint context: EDR vs Antivirus.
What does beginner hunting look like?
A hypothesis drives queries across SIEM and EDR telemetry, producing findings, notes and either a detection or a closed lead.
Hypothesis SIEM आणि EDR telemetry वर queries चालवतो, findings, notes आणि detection किंवा closed lead तयार करतो.
Hypothesis SIEM और EDR telemetry पर queries चलाता है, findings, notes और detection या closed lead बनाता है.
Hunting is not:
- Random Google of exploit PoCs.
- Scanning the public internet “for practice”.
- Ignoring the alert queue while you chase cool graphs.
Hunting is:
- Structured curiosity against logs you are allowed to see.
- Mapping ideas to ATT&CK tactics at a high level for shared language.
- Feeding gaps back into detections and playbooks.
Educational warning: only hunt in labs you own or environments where your role and policy explicitly allow investigation. Unauthorised access to third-party systems is illegal — full stop.
Real incident: SolarWinds (2020) — why hunts beyond alerts matter
Public reporting on the SolarWinds 2020 supply-chain intrusion described stealthy access across many organisations. Classic blue-team lesson: some activity looked like signed software updates or subtle cloud/identity moves that signature-only waiting missed for too long. Hunters and detection engineers who asked “what unusual admin or federation changes do we see?” found more than teams that only closed SIEM tickets.
Takeaways (vertical):
- What happened — widespread supply-chain compromise with long dwell themes in public analyses.
- What went wrong (theme) — trust in update channels + gaps in detecting “legit-looking” admin behaviour.
- Care-take — hunt identity and software distribution anomalies, not only malware hashes.
- Care-take — baseline “normal admin” so rare patterns stand out.
- Care-take — document hunts so the next analyst inherits method, not folklore.
- Bonus parallel — Target 2013 reminds us alerts without response culture also fail; hunt findings need owners.
Red Team vs Blue Team (awareness only)
Red Team — what attackers try
- Live off the land with admin tools so EDR noise looks familiar.
- Move slowly under threshold-based alerts.
- Disable or clear local logging when they can (high-level).
- Abuse valid accounts so events look “authorised”.
Blue Team — defend, detect, respond
- Central immutable-ish logs and EDR retention you can actually query.
- Hypothesis backlog aligned to your crown jewels.
- Hunt → detection promotion with false-positive tuning.
- Escalate quickly when hunt confirms compromise; do not “watch for a week” silently.
How do I run a first hunt step by step?
Step 1 — Choose a hypothesis you can test
- Bad: “Find all hackers.”
- Good: “In the last 7 days, did any user succeed on VPN from a country never seen for that user, then create a mailbox forwarding rule within 2 hours?”
- Good: “Which servers talked DNS to newly registered domains this week?” (lab or authorised DNS logs only).
Step 2 — Check data readiness
- Identity / SSO logs present?
- EDR process and network events retained?
- Email security or Microsoft 365 audit available?
- If a source is missing, the hunt output is “buy/fix visibility”, not a shrug.
Step 3 — Query narrowly first
- Start with a short window and one user population (finance, admins).
- Export a minimal field set: time (label IST), user, host, src IP, action.
- Avoid dumping entire indexes into a spreadsheet “just in case”.
Step 4 — Pivot and timeline
- Same IP elsewhere? Same host parent/child process oddities?
- Build a 5–10 line timeline a manager can read.
- Mark confidence: confirmed / suspected / benign-proved.
Step 5 — Close the loop
- Incident — open IR with evidence links.
- Detection — draft a rule (Sigma-minded) and tune in lab first.
- Close — write why it was benign; save the query for regression.
Step 6 — Lab practice (authorised only)
- Generate a controlled oddity on a VM you own (example: unusual local admin logon pattern you create yourself).
- Hunt it with Wazuh or another lab SIEM.
- Promote a detection; prove it fires once and stays quiet on normal noise.
- Never “practice” by attacking neighbour Wi‑Fi or random cloud tenants.
Hypothesis starter pack (safe ideas)
- Dormant account suddenly active at odd hours.
- New MFA device registration for privileged users.
- CloudTrail / audit: StopLogging, unusual AssumeRole, rare region.
- EDR: scripting host spawning to uncommon network destinations (describe, do not weaponise).
- DNS: bursts to domains your org never resolved before (authorised resolvers only).
Ravindra Bagale's Tip
💡 Students say "threat hunting" and watch YouTube exploit videos. In interviews talk hypothesis + data source + decision tree. One written hunt report (even if benign) carries portfolio weight. Got the pattern?
Ravindra Bagale's Tip – मराठी
💡 Students "threat hunting" म्हणतात आणि YouTube exploit video बघतात. Interview मध्ये hypothesis + data source + decision tree बोला. एक written hunt report (benign असला तरी) portfolio मध्ये weighty आहे. समजलं का pattern?
Ravindra Bagale's Tip – हिंदी
💡 Students "threat hunting" कहते हैं और YouTube exploit video देखते हैं. Interview में hypothesis + data source + decision tree बोलो. एक written hunt report (benign हो तब भी) portfolio में weighty है. समझ में आया pattern?
Care-take — hunting that stays ethical and useful
- Written scope and ticket for every prod hunt.
- Privacy: minimise access to HR / medical fields.
- Time-box: 90 minutes for a beginner hunt cycle, then document.
- Share queries in a team repo with comments.
- Pair junior + senior until note quality is consistent.
- Measure “detections born from hunts”, not vanity query counts.
How do I fix common hunting mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Hunt finds nothing useful | No hypothesis / wrong logs | Rewrite question; fix visibility first |
| Giant CSV nobody reads | No field discipline | Time, actor, host, action only |
| Same hunt every week, no rules | No promotion step | Template: hunt → Sigma/SIEM rule draft |
| Legal scare | Out-of-scope systems | Own lab or explicit authorisation only |
| Alert queue ignored | Hunt cosplay | Cap hunt hours; protect L1 capacity |
| “APT name” cosplay | Ego-driven labels | Stick to evidence and ATT&CK IDs carefully |
Try it at home
On logs you own (home lab SIEM or a CSV of your own auth stubs):
- Write one hypothesis in a single sentence.
- List the three fields you will query.
- Produce a five-line timeline (times in IST labelled).
- Decide: incident / new detection / close — with one reason each path.
- Write the SolarWinds lesson in your own words (trust + stealthy admin themes).
Learn it properly
Course lessons:
Related guides: SIEM for SOC · ATT&CK + Sigma · Windows logs + Sysmon · IR first 24 hours · Python for SOC
Got it? Hunt = hypothesis → authorised telemetry → notes → IR/detection/close. SolarWinds-era lesson: wait-for-alert alone is not enough. Scope and ethics first. Next: learn Kubernetes security basics.
समजलं का? Hunt = hypothesis → authorised telemetry → notes → IR/detection/close. SolarWinds-era lesson: wait-for-alert only कामच नाही. Scope आणि ethics first. आता Kubernetes security basics शिका.
समझ में आया? Hunt = hypothesis → authorised telemetry → notes → IR/detection/close. SolarWinds-era lesson: wait-for-alert alone काफी नहीं. Scope और ethics first. आगे Kubernetes security basics सीखो.
Frequently asked questions
What is threat hunting?
Proactive, hypothesis-driven search through telemetry you are allowed to see — not waiting only for SIEM alerts.
How is hunting different from alert triage?
Triage reacts to fired rules; hunting starts from a question and may create new rules afterward.
Can I hunt on the public internet?
No. Use labs you own or environments where policy authorises investigation.
What makes a good first hypothesis?
Specific, time-bounded and mapped to real log sources — not “find all APT activity”.
How does SolarWinds relate?
Public lessons stressed stealthy, trusted-looking activity that signature-only waiting missed too long.
Where are deeper lessons?
SOC/SIEM chapters, ATT&CK/Sigma guide and Windows Sysmon logging guide.