← Tiers

Analyst Tier 3

In development

Threat Hunting, Forensics & Malware

Hunting starts where alerting stops: forming a hypothesis about how an adversary would operate in your environment and going to look, with nothing flagging it for you. Alongside it sits the evidence work: reconstructing what a binary did and what it touched, well enough to stand behind the answer.

What this stage covers

  • Hypothesis-driven hunting against a live estate
  • Host and memory forensics to reconstruct and defend a timeline of what happened
  • Static and dynamic triage of a suspicious binary
  • Building the detection that would have caught this

What you should be able to do

  • Form and test a hunting hypothesis without an alert to anchor it
  • Recover an attack timeline from host artefacts, and produce evidence that holds up to scrutiny
  • Triage unknown malware safely and describe its behaviour
  • Turn a finding into a rule that fires on its own

The path through it

Not written yet

There is no material or lab for this stage today. The outline above is what it will cover; nothing is listed here until it genuinely exists. Tiers 1 and 2 are the stages with material written.

Start at Tier 1 →

Every technique these stages touch is written up in the TTP Catalog, which spans all three tiers rather than belonging to any one of them.