Behind the Scenes: The Daily Grind of Threat Hunter | by Kostas | Medium
I recently shared a command on Twitter and asked folks if they thought this was something fishy. I want to take this opportunity to walk you through the steps that a threat hunter takes in day-to-day operations. This includes formulating a hypothesis, developing a query, and conducting an investigation. Below is the poll I shared on Twitter and the final results that show the majority of people who thought this activity was malicious. The command: "cmd.exe" /d /c "C:\Users\ \AppData\Roaming\cmk.exe /d /c whoami" In the comments, most people shared that the command and the surrounding context could be malicious and warranted a closer look. Although I wrote up a detailed response highlighting the steps I took to investigate this, I decided to document everything through a blog post so everyone could use it as a reference, as not everyone has a Twitter account. In my case, it all started from a threat hunt when I wanted to look for the execution of renamed Windows binaries from an ab
Member-only story Threat Hunting Incident Response Information Security Investigation Behind the Scenes: The Daily Grind of Threat Hunter Kostas 7 min read · Nov 29, 2023 -- 1 Listen Share I recently shared a command on Twitter and asked folks if they thought this was something fishy. I want to take this opportunity to walk you through the steps that a threat hunter takes in day-to-day operations. This includes formulating a hypothesis, developing a query, and conducting an investigation. Below is the poll I shared on Twitter and the final results that show the majority of people who thought t
Explore this link on the map →related reading
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- More on Threat Huntingtaosecurity.blogspot.com
- Learning By Writingcold-takes.com
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Security incident disclosure — July 2026huggingface.co
- Insider Threat: Hunting and Detecting | Google Cloud Blogcloud.google.com
- Introducing Sift: Automated Threat Huntinggreynoise.io
- Mediumdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi