logo

Questions From a Beginner Threat Hunter

ID: 22046128-f296-5add-a071-d3596ca87bbb

STIX ID: report--22046128-f296-5add-a071-d3596ca87bbb

Feed Name: Black Hills Infosec Blog

Date Published: 2025-01-30

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This Q&A primer distinguishes threat hunting from passive detection, outlines the processes, data sources, and knowledge required to perform hunts, explains stealthy techniques like C2 over DNS and associated indicators (e.g., increased DNS queries, TCP/443 traffic without TLS, unusual PowerShell activity), and recommends tools and tactics for effective investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.