ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
NameTypeURLNotes
2
Hexacorn LtdArticle
http://www.hexacorn.com/blog/2016/12/12/a-few-ideas-to-mess-around-with-threat-hunting-and-edr-software-anti-threat-huntinganti-edr
3
Hexacorn LtdArticle
http://www.hexacorn.com/blog/2015/12/08/the-comprehensive-list-of-ir-sources-and-alerts-work-in-progress
4
MSP HubArticlehttp://themsphub.com/detection-response-begin
5
CobaltStrikeToolhttp://blog.cobaltstrike.com/2016/09/22/cobalt-strike-3-5-unix-post-exploitation
6
OptivArticlehttps://www.optiv.com/blog/mssql-agent-jobs-for-command-execution
7
JPCERT/CCArticlehttp://blog.jpcert.or.jp/.s/2016/01/windows-commands-abused-by-attackers.htmlHunt
8
JPCERT/CCArticlehttp://www.jpcert.or.jp/english/pub/sr/ir_research.htmlHunt, Lateral Movement
9
SANSArticlehttps://isc.sans.edu/diary/Windows+Events+log+for+IRForensics+%2CPart+1/21493
10
Jack CrookTTPshttp://findingbad.blogspot.com/2016/09/categories-of-abnormal.html
11
Jack CrookLateral Movementhttps://findingbad.blogspot.com/2016/08/hunting-lateral-movement.html
12
Jack CrookMetricshttps://findingbad.blogspot.ch/2016/11/the-hunting-cycle-and-measuring-success.html
13
Jack CrookBloghttps://findingbad.blogspot.com/2016/07/my-thoughts-on-threat-hunting.html
14
Jack CrookBloghttps://findingbad.blogspot.com/2017/01/hunting-what-does-it-look-like.html
15
That SecurityArticlehttps://fl0x2208.wordpress.com/2016/08/15/threat-hunting-and-pyramid-of-pain
16
SANSArticle
https://digital-forensics.sans.org/blog/2016/03/04/the-problems-with-seeking-and-avoiding-true-attribution-to-cyber-attacks
17
FireEyeArticlehttps://www.fireeye.com/blog/threat-research/2015/10/shim_shady_live_inv.html
18
FuzzToolhttp://pages.cs.wisc.edu/~bart/fuzz
19
WikipediaArticlehttps://en.wikipedia.org/wiki/Hunter-killer_teamRandom
20
CrowdStrikeVideo
https://www.crowdstrike.com/resources/crowdcasts/using-proactive-hunting-to-reveal-human-motive-defeat-targeted-attacks
21
EndGameArticlehttps://www.endgame.com/blog-categories/hunt
22
SANSArticle
https://www.sans.org/reading-room/whitepapers/analyst/who-what-where-when-effective-threat -hunting-36785
Opens to PDF.
23
SANSArticle
https://www.sans.org/reading-room/whitepapers/threats/generating-hypotheses-successful-threat-hunting-37172
Opens to PDF.
24
SANSArticlehttps://www.sans.org/reading-room/whitepapers/analyst/threat-hunting-open-season-adversary-36882Opens to PDF.
25
Matthew DemaskeArticlehttp://www.adaptforward.com/2016/05/threat-hunting-and-forensics-are-different
26
Harlan CarveyArticlehttp://windowsir.blogspot.co.uk/2013/07/howto-track-lateral-movement.html
27
Harlan CarveyArticlehttp://windowsir.blogspot.com/2015/06/hunting-and-knowing-what-to-huntnot-for.html
28
x0rzArticlehttps://medium.com/@x0rz/threat-hunting-on-simple-tricks-part-2-8d8f6af75335#.wy3c1kmvh
29
BlindSeekerArticlehttps://blindseeker.com/blahg/?p=830
30
Scott J. RobertsArticlehttp://sroberts.github.io/2015/04/21/hunting-tools
31
Scott J. RobertsArticlehttps://sroberts.github.io/2015/04/14/ir-is-dead-long-live-ir
32
Andrew CaseVideohttps://www.youtube.com/watch?v=751bkSD2Nn8
33
David Biancobloghttp://detect-respond.blogspot.co.uk/2015/10/a-simple-hunting-maturity-model.html
34
David BiancoBloghttp://detect-respond.blogspot.com/2016/11/hunting-for-malware-critical-process.html
35
David BiancoArticlehttp://www.darkreading.com/risk/cyber-hunting-5-tips-to-bag-your-prey/a/d-id/1319634
36
David BiancoArticlehttp://threathunting.net
37
David BiancoArticlehttps://github.com/ThreatHuntingProject/ThreatHunting
38
SqrrlArticlehttp://sqrrl.com/solutions/cyber-threat-hunting
39
SqrrlArticlehttp://blog.sqrrl.com/the-cyber-hunting-maturity-model
40
SqrrlArticlehttp://blog.sqrrl.com/the-threat-hunting-reference-model-part-2-the-hunting-loop
41
SqrrlArticlehttp://blog.sqrrl.com/topic/hunting-how-tos
42
SqrrlArticlehttps://sqrrl.com/threat-hunting-reference-guide
43
FortuneArticlehttp://fortune.com/2016/09/27/machine-learning
44
ActiveResponseArticlehttp://www.activeresponse.org/building-threat-hunting-strategy-with-the-diamond-model
45
Samuel AlonsoArticlehttps://cyber-ir.com/2016/01/21/cyber-threat-hunting-1-intro
46
NSAArticle
https://www.iad.gov/iad/library/ia-guidance/security-configuration/applications/spotting-the-adversary-with-windows-event-log-monitoring.cfm
47
Microsoft
Windows Event Logs Win10/Server2016
https://download.microsoft.com/download/7/9/F/79F3E0B9-4A00-4D15-9953-045BC9BE9338/Windows%2010%20and%20Windows%20Server%202016%20Security%20Auditing%20and%20Monitoring%20Reference.docx
Opens to docx.
48
Microsoft
Windows Event Logs Win8/Server2012
https://download.microsoft.com/download/2/4/9/2494439D-545D-4CC9-ABB3-E95949AA940A/Windows
%208%20and%20Windows%20Server%202012%20Security%20Event%20Descriptions.xls
Opens to xls.
49
Microsoft
Windows Event Logs Win7/Server2008R2
https://download.microsoft.com/download/2/D/F/2DF05493-32E0-465B-8BE2-78AFED9EE456/Windows
%207%20and%20Windows%20Server%202008%20R2%20Security%20Event%20Descriptions.xls
Opens to xls.
50
Microsoft
Windows Event Logs WinVista/Server2008
https://download.microsoft.com/download/5/1/d/51d9816a-6eb2-4fff-8f1d-b11bcdf5811d/Vista_2
008_Security_Event_Descriptions.xls
Opens to xls.
51
EventIDWindows Event Logshttp://www.eventid.net
52
Ultimate Windows SecurityWindows Event Logshttp://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx
53
RedTeamBlueTeamArticlehttp://www.redblue.team/2015/09/spotting-adversary-with-windows-event.html
54
RedTeamBlueTeamArticlehttp://www.redblue.team/2015/09/spotting-adversary-with-windows-event_21.html
55
SANSTTPs
https://www.sans.org/reading-room/whitepapers/analyst/killing-advanced-threats-tracks-intelligent-approach-attack-prevention-35302
Opens to PDF.
56
SANSTTPs
https://www.sans.org/reading-room/whitepapers/critical/uncovering-indicators-compromise-ioc-powershell-event-logs-traditional-monitorin-36352
Opens to PDF.
57
SANSWindows Event Logs
https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262
Opens to PDF.
58
Michael GoughCheatSheetshttp://www.malwarearchaeology.com/cheat-sheets
59
Michael GoughWindows Event Logs
https://conf.splunk.com/session/2015/conf2015_MGough_MalwareArchaelogy_SecurityCompliance_FindingAdvnacedAttacksAnd.pdf
Opens to PDF.
60
Michael GoughBloghttp://hackerhurricane.blogspot.com
61
Gerard LayguiPass The Hashhttp://cybersecology.com/PassTheHashForensics.pdfOpens to PDF.
62
Harmj0y (Will)SCCMhttp://www.harmj0y.net/blog/tag/sccm
63
Harmj0y (Will)PowerSploithttps://github.com/HarmJ0y/CheatSheets/blob/master/PowerSploit.pdf
Opens to PDF, PowerSploit Cheatsheet.
64
Harmj0y (Will)PowerShell Empirehttps://github.com/PowerShellEmpire/PowerTools
65
CarbonBlackVideohttps://www.brighttalk.com/webcast/11191/230359
66
Bsides CincyVideo
http://www.irongeek.com/i.php?page=videos/bsidescincy2015/bsidescincy-2015-01-lateral-movement-harlan-carvey
Lateral Movement Harlan Carvey
67
SANSVideohttps://www.youtube.com/watch?v=JKRTvCbgI2c
Finding Unknown Malware Alissa Torres
68
SANSVideohttps://www.youtube.com/watch?v=gIsxagDBnOk
Malware Can Hide But It Must Run Alissa Torres
69
SANSVideohttps://www.youtube.com/watch?v=ebPKUWqAk7U
Detecting Persistence Mechanisms Alissa Torres
70
Matthew LichtenbergerVideo
http://www.irongeek.com/i.php?page=videos/derbycon6/539-packetko-data-exfiltration-via-port-knocking-matthew-lichtenberger
DerbyCon 2016
71
BSides AugustaVideo
http://www.irongeek.com/i.php?page=videos/bsidesaugusta2016/living-in-america05-hunting-defense-against-the-dark-arts-jacqueline-stokes-danny-akacki-and-stephen-hinck
Jacqueline Stokes, Danny Akacki and Stephen Hinck
72
@_wald0, @CptJesus, and @harmj0y
Toolhttps://github.com/adaptivethreat/BloodHound
73
NCC GroupToolhttps://github.com/nccgroup
74
tclahrToolhttps://github.com/tclahr/uac
75
RecordedFutureBloghttps://www.recordedfuture.com/web-shell-analysis-part-1Web Shells
76
RecordedFutureBloghttps://www.recordedfuture.com/web-shell-analysis-part-2Web Shells
77
gwernBloghttp://www.gwern.net/Black-market%20survivalBlack Markets
78
FireEyeBloghttps://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.htmlPowerShell
79
Team CymruBloghttp://www.team-cymru.org/darknet.htmlDarkNet
80
SensePostToolhttps://github.com/sensepost/DETData Exfiltration ToolKit
81
SensePostToolhttps://github.com/sensepostVarious Tools
82
ActiveDirectory SecurityBloghttps://adsecurity.org/?p=2910
Red Teaming Active Directory
83
Rapid7Toolhttps://www.rapid7.com/free-toolsVarious Tools
84
Rapid7Videohttps://www.rapid7.com/resources/using-windows-event-logs-to-detect-lateral-movementLateral Movement
85
TaniumBloghttps://blog.tanium.com/hunting-rogue-powershell-profilesPowerShell
86
EvilFingersToolhttps://www.evilfingers.com/tools/index.php
87
Amir.H ShahinCheatSheethttps://github.com/sh4hin/MobileApp-Pentest-CheatsheetPenTesting
88
WireLurkerToolhttps://github.com/PaloAltoNetworks/WireLurkerDetector
89
Josh LiburdiArticlehttps://medium.com/@jshlbrd/hunting-for-powershell-using-heatmaps-69b70151fa5dHunt, PowerShell
90
enigma0x3Articlehttps://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-objectLateral Movement Part 1
91
enigma0x3Articlehttps://enigma0x3.net/2017/01/23/lateral-movement-via-dcom-round-2Lateral Movement Part 2
92
Marc Rivero LópezArticlehttps://medium.com/@seifreed/hunting-net-malware-40235e11dc05Hunt, Malware
93
Ryan FyffeArticlehttps://www.crowdstrike.com/blog/open-source-active-reconnaissance-red-teamHunt
94
Chad TilburyVideohttp://forensicmethods.com/hunting-powershell-command-linesHunt, PowerShell
95
ArticleArticlehttp://www.exploit-monday.com/2017/01/powershell-is-not-special-offensive.htmlHunt, PowerShell
96
Ian Barton, boingomw, Deloitte
Articlehttps://github.com/boingomw/Lazerbearsharkpig/tree/master/pretty_feed_linksHunt
97
Monnappa KAMonnappa KAhttps://cysinfo.com/detecting-deceptive-hollowing-techniques
Hunt, HollowFind, Volatility
98
Vector8Articlehttps://www.vector8.io/blog/what-is-huntingHunt
99
DFIR.itArticlehttps://dfir.it/blog/2015/08/12/webshell-every-time-the-same-purposeHunt, Web Shells
100
DFIR.itArticlehttps://dfir.it/blog/2016/01/18/webshells-every-time-the-same-story-dot-dot-dot-part2Hunt, Web Shells