Hunting Advanced Persistent Threats
Overview
Cybersecurity skill for hunting advanced persistent threats. Follows industry best practices and security standards.
When to Use
Trigger phrases:
- "hunting advanced persistent threats"
- "Conducting proactive threat hunting sprints (typically 2–4 week cycles) based on"
- "A UEBA alert or anomaly detection system flags behavioral deviations warranting"
- "A peer organization or ISAC sharing partner reports active APT compromise and yo"
Use this skill when:
- Conducting proactive threat hunting sprints (typically 2–4 week cycles) based on newly published APT intelligence
- A UEBA alert or anomaly detection system flags behavioral deviations warranting deeper investigation
- A peer organization or ISAC sharing partner reports active APT compromise and you need to validate your own exposure
Do not use this skill as a substitute for incident response when a confirmed breach is in progress — escalate to IR procedures (NIST SP 800-61).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with telemetry retention (CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne) covering 30+ days
- Access to MITRE ATT&CK Navigator for hypothesis development
- Network flow data (NetFlow, Zeek, or Suricata logs) in a queryable SIEM
- Threat hunting platform or query interface (Velociraptor, osquery fleet, or Splunk ES)
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific advanced persistent threats techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.
- Collect Baseline Data — Gather historical logs and establish normal behavior patterns for advanced persistent threats.
- Build Detection Queries — Write detection rules, Sigma rules, or SIEM queries targeting advanced persistent threats indicators.
- Execute Hunts — Run queries against the collected data, starting with broad filters and narrowing down.
- Triage Results — Investigate alerts, filter false positives, and validate findings against known-good behavior.
- Document Findings — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.
Tools
- SIEM Platform — Central log aggregation and query execution
- Sigma Rules — Vendor-agnostic detection rule format
- MITRE ATT&CK Navigator — Technique mapping and coverage analysis
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: hunting-advanced-persistent-threats3description: Use when proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks.4license: Apache-2.05---67# Hunting Advanced Persistent Threats89## Overview1011Cybersecurity skill for hunting advanced persistent threats. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "hunting advanced persistent threats"17- "Conducting proactive threat hunting sprints (typically 2–4 week cycles) based on"18- "A UEBA alert or anomaly detection system flags behavioral deviations warranting"19- "A peer organization or ISAC sharing partner reports active APT compromise and yo"202122Use this skill when:23- Conducting proactive threat hunting sprints (typically 2–4 week cycles) based on newly published APT intelligence24- A UEBA alert or anomaly detection system flags behavioral deviations warranting deeper investigation25- A peer organization or ISAC sharing partner reports active APT compromise and you need to validate your own exposure2627**Do not use** this skill as a substitute for incident response when a confirmed breach is in progress — escalate to IR procedures (NIST SP 800-61).282930## When NOT to Use3132- When you lack proper authorization for testing33- For production systems without change management34- When the task requires legal or compliance expertise beyond technical scope353637## Prerequisites3839- EDR platform with telemetry retention (CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne) covering 30+ days40- Access to MITRE ATT&CK Navigator for hypothesis development41- Network flow data (NetFlow, Zeek, or Suricata logs) in a queryable SIEM42- Threat hunting platform or query interface (Velociraptor, osquery fleet, or Splunk ES)4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Detection Scope** — Identify the specific advanced persistent threats techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.622. **Collect Baseline Data** — Gather historical logs and establish normal behavior patterns for advanced persistent threats.633. **Build Detection Queries** — Write detection rules, Sigma rules, or SIEM queries targeting advanced persistent threats indicators.644. **Execute Hunts** — Run queries against the collected data, starting with broad filters and narrowing down.655. **Triage Results** — Investigate alerts, filter false positives, and validate findings against known-good behavior.666. **Document Findings** — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.6768## Tools6970- **SIEM Platform** — Central log aggregation and query execution71- **Sigma Rules** — Vendor-agnostic detection rule format72- **MITRE ATT&CK Navigator** — Technique mapping and coverage analysis737475## Process76771. **Reconnaissance** — Gather target information, identify attack surface, enumerate services781. **Analysis/Exploitation** — Execute the technique, analyze results, document findings791. **Reporting** — Document IOCs, write findings, provide remediation recommendations8081## Verification8283- [ ] All advanced persistent threats procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |