Case A1F9DE · Blue team / DFIR · L3 Applied
Hypothesis-Driven Threat Hunting
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Hunting assumes breach and proactively searches for activity that evaded existing detections.
- Form a hypothesis from intel or ATT&CK (e.g. persistence via WMI event subscriptions), then query the data.
- Techniques: stacking/least-frequency analysis, baselining, and pivoting on parent-child process relationships.
- Every hunt should produce an outcome: an incident, a new detection, or a documented visibility gap.
If the interviewer pushes back
- Pick one ATT&CK persistence technique and design a full hunt: hypothesis, data, query and success criteria.
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.