Threat Intelligence and Hunting
TI Enrichment
AI-powered enrichment of indicators with context, attribution likelihood, campaign linking. Natural-language querying of TI graphs has become standard. Underrated: AI-summarized briefings on emerging threats tailored to your environment.
Threat Hunting
Hypothesis generation from MITRE ATT&CK, query suggestions, anomaly surfacing. Newest wave: agentic hunting — agent generates hypotheses, runs queries, follows leads, reports findings.
How Agentic Hunting Works End-to-End
Step 1: hunter or agent selects an ATT&CK technique or actor TTP as starting hypothesis. Step 2: agent generates SIEM queries targeting that behavior. Step 3: agent runs queries, evaluates results, and decides whether evidence supports the hypothesis. Step 4: if promising, agent pivots — following lateral movement chains, correlating timestamps, enriching IPs and hashes. Step 5: agent writes a structured hunt report with findings, evidence links, and recommended follow-up detections. What changes with AI: steps 2-4 that previously required 2-4 hours of senior analyst time now take minutes — and can run in parallel across multiple hypotheses.
Contextualized TI: The Undervalued Upgrade
Ask how your analysts currently stay current on threat actor TTPs. Common answer: weekly briefings, ad hoc news monitoring, hoping the SIEM vendor updates detections. The AI-powered answer: environment-specific threat briefings that cross-reference your exposed infrastructure, your sector's current threat actors, and your existing detection coverage gaps — generated daily. The delta between "generic threat intel" and "TI contextualized to your environment" is where the real value lies.
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.