AI and Hunting
Research & insights
Practical thinking for teams turning threat context into action.
Explore threat intelligence, hunting, cloud security, detection engineering, incident response, AI governance, and security operating models.
Detection Engineering
Community Sigma and YARA Detection Exchange
How Threat Foundry approaches opt-in community sharing for Sigma and YARA detections while keeping customer rules private by default.Read articleThreat Intelligence
Tune CTI prioritization with CTI Modeling and Metric Weights
How to use Threat Foundry CTI Modeling, reporting, Auto Triage, and Metric Weights to tune CTI prioritization without creating noisy queues.Read articleThreat Hunting
Detecting lateral movement with Threat Foundry.
How Threat Foundry helps teams hunt and detect lateral movement across identity, endpoint, network, cloud, and asset context.Read articleIncident Response
The DFIR feedback loop: turn incidents into better detections.
Why incident response should produce reusable intelligence, Sigma/YARA candidates, playbooks, and telemetry improvements.Read articleEnterprise Security
Enterprise detection engineering needs governance as much as content.
Why large security programs need repeatable detection lifecycle management, field normalization, evidence review, and reporting around Sigma, YARA, and hunt workflows.Read articleVulnerability Intelligence
KEV is vulnerability intelligence, not just a patch list
How CISA KEV can help security teams prioritize exploited vulnerabilities, scope exposure, trigger hunts, and drive detection work.Read articleMidsize Business
A practical detection program for midsize businesses.
How midsize organizations can build useful threat hunting and detection workflows without needing enterprise-scale tooling or staff.Read articleMSP Strategy
How MSPs can offer threat hunting without adding a full hunt team.
A practical model for MSPs and MSSPs to package CTI-led hunting, detection review, and customer reporting with repeatable workflows.Read articleYARA and DFIR
Practical YARA for incident response teams.
How IR teams can use YARA to turn malware traits, strings, and file artifacts into reviewable detection content.Read articleSOC Operations
From CTI to triage: making SOC analyst workflows less noisy.
How SOC teams can move from raw intelligence to reviewed hunts, detections, triage, and cases without turning every feed item into work.Read articleThreat Hunting
Hunting living off the land attacks with Threat Foundry.
How to use Threat Foundry to hunt living off the land attacks by turning legitimate-tool abuse into reviewed ATT&CK-driven hunts, Sigma candidates, and evidence.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 1: From Logs to Behavior
A provider-neutral model for cloud threat hunting built around identity, control-plane activity, data movement, workload runtime, and the MITRE ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 2: AWS
How to build AWS threat hunts around CloudTrail, GuardDuty, Security Lake, IAM, S3, EKS, runtime telemetry, and the MITRE ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 3: Microsoft Azure
How to build Azure cloud hunts around Entra ID, Activity Logs, Defender XDR advanced hunting, Microsoft Sentinel, hybrid identity, and the ATT&CK Cloud matrix.Read articleCloud Hunting
Threat Hunting in the Cloud, Part 4: Google Cloud
How to build Google Cloud hunts around Security Command Center, Google Security Operations, IAM, service accounts, BigQuery, GKE, Cloud Run, and the ATT&CK Cloud matrix.Read articleThreat Hunting Program
Start with a threat hunting charter before buying more tools.
How mature hunt programs define mission, scope, PIRs, authority, cadence, and handoffs before scaling technology.Read articleThreat Intelligence
The power of information sharing in threat intelligence
Why threat intelligence sharing is a force multiplier when it is timely, trusted, contextual, and tied to hunt and detection workflows.Read articleThreat Hunting
Why TTP-driven hunting beats IOC chasing.
Why durable threat hunting starts with adversary behavior, not just disposable indicators.Read articleThreat Blueprints
Getting the most from Threat Blueprints
A practical guide to turning architecture context, data flows, attack paths, findings, and remediations into an operating security workflow.Read articleThreat Intelligence
How to leverage CTI across the Threat Foundry platform
Move selected intelligence through normalization, review, prioritization, hunting, detection, investigation, and reporting without losing provenance.Read articleNo articles match this topic.