Sold by Mighty Ape
Stop chasing alerts-start hunting adversaries. Cyber Threat Hunting: Tools and Techniques for Modern SOC Teams is a hands-on field guide for blue teamers who want to move beyond reactive triage. You’ll learn a repeatable, hypothesis-driven approach to uncover stealthy attackers across endpoint, identity, network, and cloud-then turn those discoveries into durable detections.
What you’ll learn
Hunt methodology: baselining, forming hypotheses, scoping data sources, and measuring outcomes (MTTD/MTTR, coverage).
Telemetry that matters: Sysmon/Windows Event IDs, Linux auditd, macOS logs, EDR and identity signals, Zeek/Suricata, DNS/HTTP, CloudTrail/AD/Azure AD/Okta.
Query & detect: craft high-signal hunts with KQL (Microsoft), SPL (Splunk), and Elastic queries; pivoting, stacking, and outlier analysis.
Technique coverage: map hunts to MITRE ATT&CK (lateral movement, credential access, persistence, C2), plus living-off-the-land behaviors.
Detection engineering: Sigma → SIEM, YARA for triage, detection-as-code, versioning, testing, and continuous improvement.
Forensics & triage: process trees, memory snapshots (Volatility), artifact triage, and enrichment/automation playbooks.
Cloud & SaaS hunts: IaaS control planes, workload metadata, serverless traces, and identity-centric anomalies.
Operationalizing hunts: purple teaming, runbooks, metrics, dashboards, and building a hunt program that scales.
Packed with ready-to-run examples, checklists, and playbooks, this book helps SOC analysts, incident responders, and detection engineers find what your SIEM misses-and keep it from coming back. Grab the eBook, paperback, or hardcover today and start hunting with confidence.
We are committed to protecting your rights under the Consumer Guarantees Act and working with our suppliers to assist with warranty claims. Products sold by Mighty Ape will be covered by a Manufacturer's Warranty for at least a one-year period from the date of purchase.
Your warranty will cover any manufacturing defects which, if existing, will present themselves within this warranty period.
Your warranty will not cover normal wear and tear, faults caused by misuse, and accidents which cause damage or theft caused after delivery. Using the product in a way it is not designed for will void your warranty.
Please refer to our Help Centre for more information.