Threat-Informed Hunting
What is it?
Threat-informed hunting uses intelligence about real adversary behavior — techniques, tools, targeted sectors — to decide what to hunt for, instead of hunting randomly. It aims the limited hunting time at the behaviors most likely to matter for THIS organization.
Why it matters
Random hunting burns time on unlikely threats; threat-informed hunting concentrates effort where the real risk is, making a small team effective.
Where you see it
The link between the CTI team's reporting and the hunt team's plan — the subject of the whole Threat Intelligence path.
What normal looks like
Hunt plans that cite why a behavior was chosen: a sector-relevant campaign, a newly disclosed technique, a control weakness.
What suspicious looks like
Not applicable directly — this is a hunt-selection discipline, not a finding.
How analysts investigate
By translating an intelligence report's techniques (often ATT&CK-mapped) into concrete, testable hunts in the organization's own telemetry.
Common beginner mistakes
- Hunting the technique that is trending on the internet rather than the one relevant to your environment and sector.
Intelligence reports a campaign targeting Gulf retailers with credential theft followed by scheduled-task persistence. Qasr is a Gulf retailer. That report just chose the hunt team's next three hunts for them.
Quick check
Why is the reported campaign a strong hunt driver for Qasr specifically?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.