惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
L
LangChain Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
D
Docker
WordPress大学
WordPress大学
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Stack Overflow Blog
Stack Overflow Blog
有赞技术团队
有赞技术团队
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MongoDB | Blog
MongoDB | Blog
博客园 - Franky

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Bring Your Own Hunts to HUNTER
Intel 471 · 2024-12-19 · via Intel 471 Blog

You asked and the Intel 471 engineering team delivered. As a HUNTER customer utilizing the Hunt Management Module (HMM), you can now “bring your own” (BYO) threat hunting content to the HUNTER threat hunting platform. This enhancement enables your threat hunting team to map your hunt queries and activities to our tried-and-tested methodology for managing hunts and measuring hunt performance metrics that matter to your organization. 

BYO hunt content is an enhancement to the HUNTER HMM, an industry-leading centralized hunt management framework that enables consistent and repeatable hunt practices, whether you’re using hunt packages created by your internal teams or one from the HUNTER platform’s expanding library of hunt packages that our expert hunters create. With this latest Hunt Management Module enhancement, users of the HMM can add their own contextual threat intelligence, analyst notes, and research to their custom hunts in line with the HUNTER methodology. The HMM enables hunt leaders to assign, track, and manage hunts, store and manage hunt queries and findings, and measure key hunt performance metrics that demonstrate return on investment for hunt activity.     

Threat hunting teams now can maximize their internally built hunt packages that focus on the approximate 10% of threats unique to their organization, industry, or a localized risk. This enhancement is a game-changing complement to the HUNTER hunt packages that address up to 90% or so of emerging and ongoing threats. HUNTER hunt packages created by our threat hunters have been verified by our experts to identify advanced behaviors, threats, and tactics, techniques and procedures (TTPs) that have bypassed reactive detection methods. Each package contains pre-validated queries that hunters can deploy within minutes on most major EDR, NDR, and SIEM platforms, helping them hunt down emerging threats and widely used malicious behaviors in their environment faster. 

How does BYO hunts work on HUNTER? 

BYO hunt content allows customers with the HMM to keep all their hunt findings, evidence, and remediation in one place where they can leverage the module’s metrics and reporting for their hunt content and our hunt packages. Customers can align their BYO hunt content with the contextual intelligence and documentation we continually update in our HUNTER hunt packages, such as  up-to-date threat intelligence and new TTPs, tactical runbooks, contextual information, and documentation our threat hunters provide to guide analysts throughout the hunt lifecycle. Just like our HUNTER packages, customers can also tag custom hunt packages with threat actors and map them to MITRE ATT&CK techniques. 

All custom hunt content will be included in the HMM’s Hunt Module Dashboard, Reports, and Metrics, enabling teams to quickly view hunt performance metrics, such as activity, packages used, and threat actor and technique findings. Customers can create custom Hunt Templates, and then either add their content alongside HUNTER hunt packages or create net-new Hunt Templates based on their hunts. After creating a custom hunt package with their own hunt queries, customers can then add their context and content to their packages as outlined in the images further below. 

Customers are presented the same hunt methodology the HUNTER hunt team uses to apply the following information:

  1. Query Logic per HUNTER support ToolDeployment Requirements
  2. Contextualized Intelligence:Actors, Malware, SeverityMITRE ATT&CK TTP, Kill Chain, Diamond ModelThreat Category, Target OSes
  3. Analyst Notes, Threat Descriptions
  4. Reference Links
  5. Response ActionsAnalyst RunbookMitigation Recommendations

Image 1: Add Custom Hunt Packages with the Hunt Module Template

Image 1: Add Custom Hunt Packages with the Hunt Module Template

Image 2: Add Hunt Queries to a Custom Hunt Package

Image 2: Add Hunt Queries to a Custom Hunt Package

Image 3: Add your own contextual information to Custom Hunt Packages

Image 3: Add your own contextual information to Custom Hunt Packages

Image 4: Add your research notes to Custom Hunt Packages

Image 4: Add your research notes to Custom Hunt Packages

This update to the Hunt Management Module is another in our ongoing support of customers that want to bring their own content to the HUNTER platform. Stay tuned for further developments in early 2025!