Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
What Threat Hunting Is
TheoryBeginner14 minThreat Hunting

Threat-Informed Hunting

What is it?

Threat-informed hunting uses intelligence about real adversary behavior — techniques, tools, targeted sectors — to decide what to hunt for, instead of hunting randomly. It aims the limited hunting time at the behaviors most likely to matter for THIS organization.

Why it matters

Random hunting burns time on unlikely threats; threat-informed hunting concentrates effort where the real risk is, making a small team effective.

Where you see it

The link between the CTI team's reporting and the hunt team's plan — the subject of the whole Threat Intelligence path.

What normal looks like

Hunt plans that cite why a behavior was chosen: a sector-relevant campaign, a newly disclosed technique, a control weakness.

What suspicious looks like

Not applicable directly — this is a hunt-selection discipline, not a finding.

How analysts investigate

By translating an intelligence report's techniques (often ATT&CK-mapped) into concrete, testable hunts in the organization's own telemetry.

Common beginner mistakes

  • Hunting the technique that is trending on the internet rather than the one relevant to your environment and sector.

Intelligence reports a campaign targeting Gulf retailers with credential theft followed by scheduled-task persistence. Qasr is a Gulf retailer. That report just chose the hunt team's next three hunts for them.

Quick check

Why is the reported campaign a strong hunt driver for Qasr specifically?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.