DEV Community

Cover image for Threat Hunting: What I Learned from TryHackMe
Vimal Mudalagi
Vimal Mudalagi

Posted on

Threat Hunting: What I Learned from TryHackMe

Task 1 — Introduction

What the room covers

  • What Threat Hunting is.
  • Difference between Threat Hunting and Incident Response.
  • What threat hunters search for.
  • Different hunting approaches.
  • Hunting methods and techniques.
  • Applying concepts to realistic scenarios.

Task 2 — What Is Threat Hunting?

Threat Hunting

  • Systematic, proactive search for malicious activity that may have evaded detection systems.
  • Hunters do not wait for alerts.
  • They search systems, logs and networks for missed malicious activity.
  • Goal is to find threats before attackers achieve their objectives.

Why it is needed

  • Security systems are not perfect.
  • Attackers may:
    • Use zero-day exploits.
    • Modify tools to evade detection.
    • Operate slowly to avoid alarms.

Threat Hunting vs Incident Response

Aspect Threat Hunting Incident Response
Trigger Self-initiated Security alert/detection
Approach Proactive Reactive
Timeline Before compromise is obvious After threat is detected
Outcome Improve detections Containment + remediation
Example Hunter finds suspicious PowerShell before an alert Alert fires → IR investigates and contains
  • Threat hunting finds threats missed by detection.
  • IR contains/removes discovered threats.
  • IR findings can improve future detection and hunting.
  • Both disciplines work together. citeturn1view0

Dwell Time

  • Dwell time: average time an attacker remains undetected after initial compromise.
  • Room states typical 2024–2025 dwell times as 20–30 days.
  • Advanced attackers may remain for months/years.
  • During dwell time attackers can:
    • Perform reconnaissance.
    • Steal credentials.
    • Move through the network.
    • Exfiltrate data.
  • Longer dwell time → potentially greater damage.
  • Threat hunting aims to reduce dwell time.

Real-world example

  • Financial organization receives intelligence about an attack group.
  • Hunter searches logs for related indicators.
  • Finds unusual PowerShell activity.
  • Attacker had been inside for 14 days without automated detection.
  • Attacker was mapping the network and identifying valuable targets.
  • Hunting allowed IR to contain/remove the attacker before deeper progression. citeturn1view0

Task 3 — Hunting Approaches

Three foundational approaches:

  1. Hypothesis-Driven
  2. Intelligence-Driven
  3. Indicator-Driven

The selected approach depends on:

  • Available information.
  • Question being investigated.
  • Resources.
  • Threat priorities.
  • Organizational circumstances/maturity.

1. Hypothesis-Driven Hunting

  • Starts with a question or suspicion.
  • Hunter creates a hypothesis and searches for evidence to prove/disprove it.
  • Useful for a specific:
    • User.
    • System.
    • Department.
    • Attack scenario.

Example

Finance workstations suspected of phishing compromise.

Hunter searches for:

  • Suspicious PowerShell.
  • Unusual network connections.
  • Credential dumping.
  • Unexpected process spawning.

When to use

  • Specific concern exists.
  • Need focused investigation.
  • Domain knowledge about environmental risks is available.

2. Intelligence-Driven Hunting

  • Starts with external Threat Intelligence.
  • Hunter learns about threats affecting their industry/geographic region.
  • Searches the environment for evidence of those threats.
  • Uses research from:
    • Security researchers.
    • Vendors.
    • Global security community.

MITRE ATT&CK

  • Organizes adversary tactics and techniques based on real-world observations.
  • Provides standardized technique IDs.

Examples:

  • T1566.002 — Phishing / Spearphishing Link
  • T1059.001 — PowerShell
  • T1055 — Process Injection
  • T1041 — Exfiltration Over C2 Channel

Example

APT group targeting financial institutions:

  • T1566.002 → initial access.
  • T1059.001 → command execution.
  • T1041 → data theft.

Hunter searches for:

  • Matching indicators.
  • Related behavioral patterns.
  • Connections to known C2 servers.

When to use

  • Published intelligence matches your threat profile.
  • Relevant industry/geography/business model.
  • Detailed threat feeds, vendor reports or incident reports are available.

3. Indicator-Driven Hunting

Focuses on concrete Indicators of Compromise (IOCs).

Examples:

  • File hashes.
  • IP addresses.
  • Domain names.
  • Email addresses.
  • Command-line patterns.

Example

  • Threat feed provides 150 malicious file hashes.
  • Hunter searches for process execution/file creation matching those hashes.
  • Result: indicator either exists or does not.

When to use

  • Large IOC lists are available.
  • Clear/objective results are needed.
  • Automation is useful.

Selecting an Approach

Situation Approach
Specific concern about asset/user Hypothesis-driven
Threat intelligence about industry threat Intelligence-driven
Known hashes/IPs/domains from trusted source Indicator-driven

Organizations may use all three.

Questions hunters consider

  • Where might the attacker move?
  • What systems could they access?
  • How might they establish persistence?
  • Where could they go from here? citeturn1view0

Task 4 — Hunting Targets

Targets = WHAT we hunt for.

Attackers create artifacts by:

  • Executing commands.
  • Creating files.
  • Establishing network connections.
  • Modifying settings.
  • Interacting with applications.

Three main targets:

1. Known Malware

  • Search for malware already known/reported.
  • Repositories/threat feeds contain:
    • File hashes.
    • Signatures.
    • Behavioral analysis.

Tool/resource

  • VirusTotal

Example — Emotet

Possible hunting targets:

  • Emotet file hashes.
  • Launch command-line patterns.
  • C2 connections.
  • Credential-stealing behavior.
  • Lateral-movement behavior.

Challenges

  • Malware changes constantly.
  • Attackers can:
    • Recompile malware.
    • Add obfuscation.
    • Change infrastructure.
    • Create variants.
  • Old hashes may not match newer variants.
  • Zero-day malware has no known indicators.

Sources

  • Malware repositories.
  • Threat intelligence feeds.
  • Incident reports.
  • Security vendor publications.
  • Information-sharing platforms.

2. Attack Residues

  • Artifacts left behind while attackers execute their attack chain.
  • Attackers must:
    • Execute code.
    • Run commands.
    • Access files.
    • Create persistence.
    • Establish C2 communication.

Example

Attacker uses lsass.exe to dump password hashes.

Hunter may observe:

  • Unusual process creation.
  • Unexpected parent process.
  • Abnormal memory access.

Possible commands:

  • whoami
  • net user
  • ipconfig
  • tasklist

Why useful

  • Attack residues can be independent of specific malware.
  • Different attackers/tools may leave similar residues.
  • Can help detect unknown malware or zero-days.

Common residues

  • Unusual process spawning.
  • cmd.exe/PowerShell from unexpected parents.
  • Administrative-tool command execution.
  • Unexpected external IP connections.
  • Suspicious file creation.
  • Registry modifications.
  • Unusual privilege escalation.

3. Known Vulnerabilities

  • Hunt for evidence that known vulnerabilities were exploited.
  • Attackers can develop exploits quickly after disclosure.
  • Vulnerable systems remain exposed during the patching window.

Example — Log4Shell

  • CVE-2021-44228
  • Critical Log4j vulnerability.
  • Exploitation through specially crafted messages.

Hunter searches for:

  • HTTP requests containing exploit patterns.
  • Unusual Java behavior.
  • Unexpected network connections.
  • Unexpected child processes.
  • Unusual filesystem activity.

Why it matters

  • Vulnerability exploitation is a common initial-access method.
  • Hunting can identify exploitation earlier.

Integrating the 3 Targets

One hunt can combine:

  • Known malware.
  • Attack residues.
  • Vulnerability exploitation evidence.

Targets = WHAT evidence we hunt for. citeturn1view0


Task 5 — Hunting Techniques

Techniques = HOW we hunt.

Where Threat Hunters Search

Data sources include:

  • Event logs.
  • EDR data.
  • SIEM systems.
  • Network traffic/flow data.
  • DNS logs.
  • Web proxy logs.
  • Firewall logs.
  • Application logs.
  • System registry.
  • Memory.
  • Configuration files.
  • Temporary directories.
  • Backup systems.
  • Cloud services.

Important point

  • No single data source gives the complete story.
  • Hunters correlate:
    • Logs.
    • Network data.
    • Endpoint information.
  • Mature programs continuously expand visibility and data collection.

Method 1 — Attack Signatures

Attack signature = pattern indicating malicious activity.

Examples:

  • Known malware file hash.
  • Malicious command-line parameters.
  • Unusual process parent.
  • Known malicious URL pattern.
  • Registry modification at persistence location.

Example:

powershell.exe + -EncodedCommand + DownloadString
Enter fullscreen mode Exit fullscreen mode
cmd.exe spawned from winword.exe
Enter fullscreen mode Exit fullscreen mode

Example registry location:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Enter fullscreen mode Exit fullscreen mode

Used in

  • EDR.
  • SIEM.
  • Antivirus logs.
  • Firewall logs.

MITRE connection

  • PowerShell signature → T1059.001
  • Registry persistence → T1547

Effectiveness

  • Good against known threats.
  • Can miss variations and zero-days.
  • Produces clear/objective results.

Method 2 — Indicators of Compromise (IOCs)

Specific attacker artifacts:

  • File hashes.
  • IP addresses.
  • Domains.
  • Email addresses.
  • URLs.
  • Registry keys.

Hunting examples

  • Hashes → EDR/SIEM.
  • IPs → firewall/network logs.
  • Domains → DNS logs.
  • Emails → email logs.
  • URLs → web proxy logs.

Tools/platforms

  • SIEM.
  • MISP
  • Recorded Future
  • EDR.
  • Firewall logs.
  • DNS logs.

Effectiveness

  • Clear/objective results.
  • Attackers frequently change infrastructure.
  • IOCs become outdated.
  • Recent/relevant IOCs are most useful.

Method 3 — Behavioral Pattern Analysis

Looks for sequences of events that together indicate malicious activity.

Examples

Process chain

Word.exe → cmd.exe → powershell.exe → external IP
Enter fullscreen mode Exit fullscreen mode

File access

  • One user accesses hundreds of sensitive files within minutes.

Lateral movement

Remote execution on A
→ process creation on B
→ credential access on B
Enter fullscreen mode Exit fullscreen mode

Privilege escalation

Normal user process
→ SYSTEM permissions
→ sensitive file access
Enter fullscreen mode Exit fullscreen mode

Data collection

Database query
→ bulk file reads
→ archive creation
→ network transmission
Enter fullscreen mode Exit fullscreen mode

Used in

  • Advanced SIEM.
  • EDR process-tree analysis.
  • Behavioral analysis tools.

MITRE connection

Attack chains can correspond to combinations of MITRE techniques.

Effectiveness

  • Can detect attacks without known malware/IOCs.
  • Focuses on attacker actions rather than specific tools.
  • False positives are possible.
  • Normal administrative activity can resemble attack behavior.

Method 4 — Logical Queries & Anomaly Detection

Uses conditional logic to identify suspicious activity that differs from normal behavior.

Examples

  • Administrator commands at 3 AM.
  • SYSTEM account running interactive commands.
  • User accessing normally unused data directories.
  • Internal system connecting to unusual ports.
  • Password change for inactive account.
  • Non-IT user downloading large amounts of files.

Example query patterns

EventCode=4688
where ParentProcessName NOT IN [explorer.exe, cmd.exe]
AND User = SYSTEM
AND CommandLine IN [whoami, net user, ipconfig]
Enter fullscreen mode Exit fullscreen mode
EventCode=4663
where TargetUserName NOT IN [IT_team]
AND ObjectName LIKE "*\sensitive_data\*"
AND count > 50
Enter fullscreen mode Exit fullscreen mode
Network
where SourceIP IN [10.*, 192.168.*]
AND DestinationPort NOT IN [80, 443, 53, 22, 21]
AND BytesSent > 1000000
Enter fullscreen mode Exit fullscreen mode
EventCode=4723
where TargetUserName NOT IN [active_users]
AND SubjectUserName = Administrator
Enter fullscreen mode Exit fullscreen mode

Used in

  • Splunk SPL
  • ELK / Elasticsearch Query Language
  • Azure KQL
  • EDR advanced hunting.
  • Security data lakes.

MITRE connection

Queries can target techniques such as:

  • T1087 — Account Discovery
  • T1005 — Data from Local System

Effectiveness

  • Highly customizable.
  • Can detect unknown attacks through abnormal behavior.
  • Requires understanding normal environment behavior.
  • Effective query construction can be difficult.

Combining Hunting Methods

Effective hunts rarely use only one method.

Example:

  1. Load IOC lists into SIEM.
  2. Search for behavioral patterns matching known attackers.
  3. Create logical queries for similar activity from unknown attackers.

Layered hunting → known + unknown threat detection. citeturn1view0


Task 6 — Practical

Scenario

You are a threat hunter at a financial-services organization.

  • Threat intelligence identifies APT-Serpent.
  • APT-Serpent targets organizations in the sector.
  • No alerts have fired.
  • Goal: proactively determine whether the attacker has gained a foothold.

Practical questions

  • Number of known APT-Serpent campaigns since 2021.
  • Phase where CustomBackdoor gets dropped.
  • Primary initial-access vector used by APT-Serpent.
  • Time interval between CustomBackdoor HTTPS C2 beacons.
  • Flag received after selecting the correct hunting approach + target. citeturn1view0

Task 7 — Conclusion

Core concepts

Threat Hunting

  • Fundamentally proactive.
  • Does not wait for alerts.
  • Searches for threats detection systems missed.
  • Especially useful during early attack stages.

3 Approaches

  1. Hypothesis-driven
  2. Intelligence-driven
  3. Indicator-driven

3 Targets

  1. Known malware
  2. Attack residues
  3. Vulnerability exploitation

4 Methods

  1. Attack signatures
  2. IOCs
  3. Behavioral pattern analysis
  4. Logical queries

Mindset

  • Suspicious thinking.
  • Methodical analysis.
  • Continuous learning.

Result of every hunt

  • Find active threats.
  • Identify detection gaps.
  • Strengthen future detection.
  • Improve understanding of attackers and the environment.

🧠 One-page memory map

                 THREAT HUNTING
                       │
        ┌──────────────┴──────────────┐
        │                             │
       WHAT                           HOW
     Targets                       Methods
        │                             │
 ┌──────┼──────┐              ┌──────┼────────┐
 │      │      │              │      │        │
Malware Residues Vulns    Signatures IOCs  Behavioral
                                      │
                                Logical Queries
Enter fullscreen mode Exit fullscreen mode

Approaches

Specific suspicion     → Hypothesis-driven

Threat Intelligence    → Intelligence-driven
        ↓
    MITRE ATT&CK

Known hashes/IPs/etc.  → Indicator-driven
Enter fullscreen mode Exit fullscreen mode

Core distinction

Incident Response → ALERT → Investigate → Respond
Threat Hunting    → HUNT  → Find threat → Improve detection
Enter fullscreen mode Exit fullscreen mode

Core objective emphasized by the room

Find threats proactively and reduce the time attackers remain undetected. citeturn1view0

Next rooms: Threat Hunting: Foothold → Pivoting → Endgame → Hunt Me I: Payment Collectors → Hunt Me II: Typo Squatters.

Top comments (0)