| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Name | Type | URL | Notes | ||||||||||||||||||||||
2 | Hexacorn Ltd | Article | http://www.hexacorn.com/blog/2016/12/12/a-few-ideas-to-mess-around-with-threat-hunting-and-edr-software-anti-threat-huntinganti-edr | |||||||||||||||||||||||
3 | Hexacorn Ltd | Article | http://www.hexacorn.com/blog/2015/12/08/the-comprehensive-list-of-ir-sources-and-alerts-work-in-progress | |||||||||||||||||||||||
4 | MSP Hub | Article | http://themsphub.com/detection-response-begin | |||||||||||||||||||||||
5 | CobaltStrike | Tool | http://blog.cobaltstrike.com/2016/09/22/cobalt-strike-3-5-unix-post-exploitation | |||||||||||||||||||||||
6 | Optiv | Article | https://www.optiv.com/blog/mssql-agent-jobs-for-command-execution | |||||||||||||||||||||||
7 | JPCERT/CC | Article | http://blog.jpcert.or.jp/.s/2016/01/windows-commands-abused-by-attackers.html | Hunt | ||||||||||||||||||||||
8 | JPCERT/CC | Article | http://www.jpcert.or.jp/english/pub/sr/ir_research.html | Hunt, Lateral Movement | ||||||||||||||||||||||
9 | SANS | Article | https://isc.sans.edu/diary/Windows+Events+log+for+IRForensics+%2CPart+1/21493 | |||||||||||||||||||||||
10 | Jack Crook | TTPs | http://findingbad.blogspot.com/2016/09/categories-of-abnormal.html | |||||||||||||||||||||||
11 | Jack Crook | Lateral Movement | https://findingbad.blogspot.com/2016/08/hunting-lateral-movement.html | |||||||||||||||||||||||
12 | Jack Crook | Metrics | https://findingbad.blogspot.ch/2016/11/the-hunting-cycle-and-measuring-success.html | |||||||||||||||||||||||
13 | Jack Crook | Blog | https://findingbad.blogspot.com/2016/07/my-thoughts-on-threat-hunting.html | |||||||||||||||||||||||
14 | Jack Crook | Blog | https://findingbad.blogspot.com/2017/01/hunting-what-does-it-look-like.html | |||||||||||||||||||||||
15 | That Security | Article | https://fl0x2208.wordpress.com/2016/08/15/threat-hunting-and-pyramid-of-pain | |||||||||||||||||||||||
16 | SANS | Article | https://digital-forensics.sans.org/blog/2016/03/04/the-problems-with-seeking-and-avoiding-true-attribution-to-cyber-attacks | |||||||||||||||||||||||
17 | FireEye | Article | https://www.fireeye.com/blog/threat-research/2015/10/shim_shady_live_inv.html | |||||||||||||||||||||||
18 | Fuzz | Tool | http://pages.cs.wisc.edu/~bart/fuzz | |||||||||||||||||||||||
19 | Wikipedia | Article | https://en.wikipedia.org/wiki/Hunter-killer_team | Random | ||||||||||||||||||||||
20 | CrowdStrike | Video | https://www.crowdstrike.com/resources/crowdcasts/using-proactive-hunting-to-reveal-human-motive-defeat-targeted-attacks | |||||||||||||||||||||||
21 | EndGame | Article | https://www.endgame.com/blog-categories/hunt | |||||||||||||||||||||||
22 | SANS | Article | https://www.sans.org/reading-room/whitepapers/analyst/who-what-where-when-effective-threat -hunting-36785 | Opens to PDF. | ||||||||||||||||||||||
23 | SANS | Article | https://www.sans.org/reading-room/whitepapers/threats/generating-hypotheses-successful-threat-hunting-37172 | Opens to PDF. | ||||||||||||||||||||||
24 | SANS | Article | https://www.sans.org/reading-room/whitepapers/analyst/threat-hunting-open-season-adversary-36882 | Opens to PDF. | ||||||||||||||||||||||
25 | Matthew Demaske | Article | http://www.adaptforward.com/2016/05/threat-hunting-and-forensics-are-different | |||||||||||||||||||||||
26 | Harlan Carvey | Article | http://windowsir.blogspot.co.uk/2013/07/howto-track-lateral-movement.html | |||||||||||||||||||||||
27 | Harlan Carvey | Article | http://windowsir.blogspot.com/2015/06/hunting-and-knowing-what-to-huntnot-for.html | |||||||||||||||||||||||
28 | x0rz | Article | https://medium.com/@x0rz/threat-hunting-on-simple-tricks-part-2-8d8f6af75335#.wy3c1kmvh | |||||||||||||||||||||||
29 | BlindSeeker | Article | https://blindseeker.com/blahg/?p=830 | |||||||||||||||||||||||
30 | Scott J. Roberts | Article | http://sroberts.github.io/2015/04/21/hunting-tools | |||||||||||||||||||||||
31 | Scott J. Roberts | Article | https://sroberts.github.io/2015/04/14/ir-is-dead-long-live-ir | |||||||||||||||||||||||
32 | Andrew Case | Video | https://www.youtube.com/watch?v=751bkSD2Nn8 | |||||||||||||||||||||||
33 | David Bianco | blog | http://detect-respond.blogspot.co.uk/2015/10/a-simple-hunting-maturity-model.html | |||||||||||||||||||||||
34 | David Bianco | Blog | http://detect-respond.blogspot.com/2016/11/hunting-for-malware-critical-process.html | |||||||||||||||||||||||
35 | David Bianco | Article | http://www.darkreading.com/risk/cyber-hunting-5-tips-to-bag-your-prey/a/d-id/1319634 | |||||||||||||||||||||||
36 | David Bianco | Article | http://threathunting.net | |||||||||||||||||||||||
37 | David Bianco | Article | https://github.com/ThreatHuntingProject/ThreatHunting | |||||||||||||||||||||||
38 | Sqrrl | Article | http://sqrrl.com/solutions/cyber-threat-hunting | |||||||||||||||||||||||
39 | Sqrrl | Article | http://blog.sqrrl.com/the-cyber-hunting-maturity-model | |||||||||||||||||||||||
40 | Sqrrl | Article | http://blog.sqrrl.com/the-threat-hunting-reference-model-part-2-the-hunting-loop | |||||||||||||||||||||||
41 | Sqrrl | Article | http://blog.sqrrl.com/topic/hunting-how-tos | |||||||||||||||||||||||
42 | Sqrrl | Article | https://sqrrl.com/threat-hunting-reference-guide | |||||||||||||||||||||||
43 | Fortune | Article | http://fortune.com/2016/09/27/machine-learning | |||||||||||||||||||||||
44 | ActiveResponse | Article | http://www.activeresponse.org/building-threat-hunting-strategy-with-the-diamond-model | |||||||||||||||||||||||
45 | Samuel Alonso | Article | https://cyber-ir.com/2016/01/21/cyber-threat-hunting-1-intro | |||||||||||||||||||||||
46 | NSA | Article | https://www.iad.gov/iad/library/ia-guidance/security-configuration/applications/spotting-the-adversary-with-windows-event-log-monitoring.cfm | |||||||||||||||||||||||
47 | Microsoft | Windows Event Logs Win10/Server2016 | https://download.microsoft.com/download/7/9/F/79F3E0B9-4A00-4D15-9953-045BC9BE9338/Windows%2010%20and%20Windows%20Server%202016%20Security%20Auditing%20and%20Monitoring%20Reference.docx | Opens to docx. | ||||||||||||||||||||||
48 | Microsoft | Windows Event Logs Win8/Server2012 | https://download.microsoft.com/download/2/4/9/2494439D-545D-4CC9-ABB3-E95949AA940A/Windows %208%20and%20Windows%20Server%202012%20Security%20Event%20Descriptions.xls | Opens to xls. | ||||||||||||||||||||||
49 | Microsoft | Windows Event Logs Win7/Server2008R2 | https://download.microsoft.com/download/2/D/F/2DF05493-32E0-465B-8BE2-78AFED9EE456/Windows %207%20and%20Windows%20Server%202008%20R2%20Security%20Event%20Descriptions.xls | Opens to xls. | ||||||||||||||||||||||
50 | Microsoft | Windows Event Logs WinVista/Server2008 | https://download.microsoft.com/download/5/1/d/51d9816a-6eb2-4fff-8f1d-b11bcdf5811d/Vista_2 008_Security_Event_Descriptions.xls | Opens to xls. | ||||||||||||||||||||||
51 | EventID | Windows Event Logs | http://www.eventid.net | |||||||||||||||||||||||
52 | Ultimate Windows Security | Windows Event Logs | http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx | |||||||||||||||||||||||
53 | RedTeamBlueTeam | Article | http://www.redblue.team/2015/09/spotting-adversary-with-windows-event.html | |||||||||||||||||||||||
54 | RedTeamBlueTeam | Article | http://www.redblue.team/2015/09/spotting-adversary-with-windows-event_21.html | |||||||||||||||||||||||
55 | SANS | TTPs | https://www.sans.org/reading-room/whitepapers/analyst/killing-advanced-threats-tracks-intelligent-approach-attack-prevention-35302 | Opens to PDF. | ||||||||||||||||||||||
56 | SANS | TTPs | https://www.sans.org/reading-room/whitepapers/critical/uncovering-indicators-compromise-ioc-powershell-event-logs-traditional-monitorin-36352 | Opens to PDF. | ||||||||||||||||||||||
57 | SANS | Windows Event Logs | https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262 | Opens to PDF. | ||||||||||||||||||||||
58 | Michael Gough | CheatSheets | http://www.malwarearchaeology.com/cheat-sheets | |||||||||||||||||||||||
59 | Michael Gough | Windows Event Logs | https://conf.splunk.com/session/2015/conf2015_MGough_MalwareArchaelogy_SecurityCompliance_FindingAdvnacedAttacksAnd.pdf | Opens to PDF. | ||||||||||||||||||||||
60 | Michael Gough | Blog | http://hackerhurricane.blogspot.com | |||||||||||||||||||||||
61 | Gerard Laygui | Pass The Hash | http://cybersecology.com/PassTheHashForensics.pdf | Opens to PDF. | ||||||||||||||||||||||
62 | Harmj0y (Will) | SCCM | http://www.harmj0y.net/blog/tag/sccm | |||||||||||||||||||||||
63 | Harmj0y (Will) | PowerSploit | https://github.com/HarmJ0y/CheatSheets/blob/master/PowerSploit.pdf | Opens to PDF, PowerSploit Cheatsheet. | ||||||||||||||||||||||
64 | Harmj0y (Will) | PowerShell Empire | https://github.com/PowerShellEmpire/PowerTools | |||||||||||||||||||||||
65 | CarbonBlack | Video | https://www.brighttalk.com/webcast/11191/230359 | |||||||||||||||||||||||
66 | Bsides Cincy | Video | http://www.irongeek.com/i.php?page=videos/bsidescincy2015/bsidescincy-2015-01-lateral-movement-harlan-carvey | Lateral Movement Harlan Carvey | ||||||||||||||||||||||
67 | SANS | Video | https://www.youtube.com/watch?v=JKRTvCbgI2c | Finding Unknown Malware Alissa Torres | ||||||||||||||||||||||
68 | SANS | Video | https://www.youtube.com/watch?v=gIsxagDBnOk | Malware Can Hide But It Must Run Alissa Torres | ||||||||||||||||||||||
69 | SANS | Video | https://www.youtube.com/watch?v=ebPKUWqAk7U | Detecting Persistence Mechanisms Alissa Torres | ||||||||||||||||||||||
70 | Matthew Lichtenberger | Video | http://www.irongeek.com/i.php?page=videos/derbycon6/539-packetko-data-exfiltration-via-port-knocking-matthew-lichtenberger | DerbyCon 2016 | ||||||||||||||||||||||
71 | BSides Augusta | Video | http://www.irongeek.com/i.php?page=videos/bsidesaugusta2016/living-in-america05-hunting-defense-against-the-dark-arts-jacqueline-stokes-danny-akacki-and-stephen-hinck | Jacqueline Stokes, Danny Akacki and Stephen Hinck | ||||||||||||||||||||||
72 | @_wald0, @CptJesus, and @harmj0y | Tool | https://github.com/adaptivethreat/BloodHound | |||||||||||||||||||||||
73 | NCC Group | Tool | https://github.com/nccgroup | |||||||||||||||||||||||
74 | tclahr | Tool | https://github.com/tclahr/uac | |||||||||||||||||||||||
75 | RecordedFuture | Blog | https://www.recordedfuture.com/web-shell-analysis-part-1 | Web Shells | ||||||||||||||||||||||
76 | RecordedFuture | Blog | https://www.recordedfuture.com/web-shell-analysis-part-2 | Web Shells | ||||||||||||||||||||||
77 | gwern | Blog | http://www.gwern.net/Black-market%20survival | Black Markets | ||||||||||||||||||||||
78 | FireEye | Blog | https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html | PowerShell | ||||||||||||||||||||||
79 | Team Cymru | Blog | http://www.team-cymru.org/darknet.html | DarkNet | ||||||||||||||||||||||
80 | SensePost | Tool | https://github.com/sensepost/DET | Data Exfiltration ToolKit | ||||||||||||||||||||||
81 | SensePost | Tool | https://github.com/sensepost | Various Tools | ||||||||||||||||||||||
82 | ActiveDirectory Security | Blog | https://adsecurity.org/?p=2910 | Red Teaming Active Directory | ||||||||||||||||||||||
83 | Rapid7 | Tool | https://www.rapid7.com/free-tools | Various Tools | ||||||||||||||||||||||
84 | Rapid7 | Video | https://www.rapid7.com/resources/using-windows-event-logs-to-detect-lateral-movement | Lateral Movement | ||||||||||||||||||||||
85 | Tanium | Blog | https://blog.tanium.com/hunting-rogue-powershell-profiles | PowerShell | ||||||||||||||||||||||
86 | EvilFingers | Tool | https://www.evilfingers.com/tools/index.php | |||||||||||||||||||||||
87 | Amir.H Shahin | CheatSheet | https://github.com/sh4hin/MobileApp-Pentest-Cheatsheet | PenTesting | ||||||||||||||||||||||
88 | WireLurker | Tool | https://github.com/PaloAltoNetworks/WireLurkerDetector | |||||||||||||||||||||||
89 | Josh Liburdi | Article | https://medium.com/@jshlbrd/hunting-for-powershell-using-heatmaps-69b70151fa5d | Hunt, PowerShell | ||||||||||||||||||||||
90 | enigma0x3 | Article | https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-object | Lateral Movement Part 1 | ||||||||||||||||||||||
91 | enigma0x3 | Article | https://enigma0x3.net/2017/01/23/lateral-movement-via-dcom-round-2 | Lateral Movement Part 2 | ||||||||||||||||||||||
92 | Marc Rivero López | Article | https://medium.com/@seifreed/hunting-net-malware-40235e11dc05 | Hunt, Malware | ||||||||||||||||||||||
93 | Ryan Fyffe | Article | https://www.crowdstrike.com/blog/open-source-active-reconnaissance-red-team | Hunt | ||||||||||||||||||||||
94 | Chad Tilbury | Video | http://forensicmethods.com/hunting-powershell-command-lines | Hunt, PowerShell | ||||||||||||||||||||||
95 | Article | Article | http://www.exploit-monday.com/2017/01/powershell-is-not-special-offensive.html | Hunt, PowerShell | ||||||||||||||||||||||
96 | Ian Barton, boingomw, Deloitte | Article | https://github.com/boingomw/Lazerbearsharkpig/tree/master/pretty_feed_links | Hunt | ||||||||||||||||||||||
97 | Monnappa KA | Monnappa KA | https://cysinfo.com/detecting-deceptive-hollowing-techniques | Hunt, HollowFind, Volatility | ||||||||||||||||||||||
98 | Vector8 | Article | https://www.vector8.io/blog/what-is-hunting | Hunt | ||||||||||||||||||||||
99 | DFIR.it | Article | https://dfir.it/blog/2015/08/12/webshell-every-time-the-same-purpose | Hunt, Web Shells | ||||||||||||||||||||||
100 | DFIR.it | Article | https://dfir.it/blog/2016/01/18/webshells-every-time-the-same-story-dot-dot-dot-part2 | Hunt, Web Shells |