THREAT HUNT LABS

Threat Hunting Reports

108 practical, evidence-focused hunting exercises.

108 reports

Threat Hunting ExerciseAnalyzing RDP Interactive Task-Manager LSASS Dump2025-07-22Threat Hunting ExerciseAnalyzing MSF Record Mic Dataset2025-07-23Threat Hunting ExerciseAnalyzing Covenant LOLBIN Wuauclt CreateRemoteThread Dataset2025-07-24Threat Hunting ExerciseAnalyzing Empire PowerDump SAM Access Dataset2025-07-25Threat Hunting ExerciseAnalyzing Covenant DCSync DCERPC DRSUAPI DsGetNCChanges Dataset2025-07-26Threat Hunting ExerciseAnalyzing SH Binary Padding DD Dataset2025-07-27Threat Hunting ExerciseAnalyzing SH ARP Cache Dataset2025-07-28Threat Hunting ExerciseAnalyzing EC2 Proxy S3 Exfiltration Dataset2025-07-29Threat Hunting ExerciseAnalyzing AWS S3 Honeypot Bucket Logs2025-07-30Threat Hunting ExerciseAnalyzing CMD Service Mod Fax Dataset2025-07-31Threat Hunting ExerciseAnalyzing Empire Persistence Registry Modification Run Keys Dataset2025-08-01Threat Hunting ExerciseAnalyzing Covenant SC Query DCERPC SMB SVCCTL Dataset2025-08-02Threat Hunting ExerciseAnalyzing PSH Python Web Server Dataset2025-08-03Threat Hunting ExerciseAnalyzing Covenant GetDomainGroup LDAP SearchRequest Domain Admins Dataset2025-08-04Threat Hunting ExerciseAnalyzing CMD Disable EventLog Service Startup Type Modification via Registry Dataset2025-08-05Threat Hunting ExerciseNext Steps: From Hypothesis to Capstone Hunt2025-08-06Threat Hunting ExerciseAnalyzing Ransomware Shadow Copy Deletion and Mass Encryption Dataset2025-08-19Threat Hunting ExerciseAnalyzing AWS IAM PassRole Privilege Escalation Dataset2025-08-20Threat Hunting ExerciseAnalyzing VPN Impossible Travel Concurrent Session Dataset2025-08-21Threat Hunting ExerciseAnalyzing Kubernetes Exec Privileged Pod Dataset2025-08-22Threat Hunting ExerciseAnalyzing Office 365 Mailbox Forwarding Rule Exfiltration Dataset2025-08-23Threat Hunting ExerciseAnalyzing Malicious Office Macro WinWord Child Process Dataset2025-08-24Threat Hunting ExerciseAnalyzing USB Removable Media Mass File Copy Dataset2025-08-25Threat Hunting ExerciseAnalyzing AD CS ESC1 Certificate Template Abuse Dataset2025-08-26Threat Hunting ExerciseAnalyzing Windows Defender Tampering PowerShell Dataset2025-08-27Threat Hunting ExerciseAnalyzing NTLM Relay to LDAP/SMB Dataset2025-08-28Threat Hunting ExerciseAnalyzing Firewall Outbound C2 Beaconing over Non-Standard Ports Dataset2025-08-29Threat Hunting ExerciseAnalyzing Firewall Egress Rule Abuse for Data Exfiltration Dataset2025-08-30Threat Hunting ExerciseAnalyzing IDS/Snort EternalBlue SMB Exploit Lateral Movement Dataset2025-08-31Threat Hunting ExerciseAnalyzing IDS JA3/TLS Fingerprint C2 Framework Detection Dataset2025-09-01Threat Hunting ExerciseAnalyzing Proxy Newly-Registered-Domain Beaconing Dataset2025-09-02Threat Hunting ExerciseAnalyzing Proxy Personal Cloud Storage Exfiltration Dataset2025-09-03Threat Hunting ExerciseAnalyzing Linux Cron Job Persistence Dataset2025-09-04Threat Hunting ExerciseAnalyzing Linux SSH authorized_keys Backdoor Dataset2025-09-05Threat Hunting ExerciseAnalyzing Linux LD_PRELOAD Rootkit Dataset2025-09-06Threat Hunting ExerciseAnalyzing Windows Golden Ticket Attack Dataset2025-09-07Threat Hunting ExerciseAnalyzing Windows Pass-the-Hash Lateral Movement Dataset2025-09-08Threat Hunting ExerciseAnalyzing Windows WMI Event Subscription Persistence Dataset2025-09-09Threat Hunting ExerciseAnalyzing AWS CloudTrail Logging Disabled - GuardDuty Evasion Dataset2025-09-10Threat Hunting ExerciseAnalyzing Azure AD Illicit OAuth Consent Grant Phishing Dataset2025-09-11Threat Hunting ExerciseAnalyzing Email BEC Wire Fraud Payment Redirect Dataset2025-09-12Threat Hunting ExerciseAnalyzing DNS DGA (Domain Generation Algorithm) Beaconing Dataset2025-09-13Threat Hunting ExerciseAnalyzing Database SQL Injection Mass Data Exfiltration Dataset2025-09-14Threat Hunting ExerciseAnalyzing EDR Reflective DLL Injection / Process Hollowing Dataset2025-09-15Threat Hunting ExerciseAnalyzing Network Rogue DHCP Server MITM Dataset2025-09-16Threat Hunting ExerciseAnalyzing Windows Scheduled Task Persistence Malicious Payload Dataset2025-09-17Threat Hunting ExerciseAnalyzing Windows Kerberoasting SPN Enumeration & Offline Cracking Dataset2025-09-18Threat Hunting ExerciseAnalyzing Windows AS-REP Roasting Against No-Pre-Auth Accounts Dataset2025-09-19Threat Hunting ExerciseAnalyzing Windows DCShadow Rogue Domain Controller Registration Dataset2025-09-20Threat Hunting ExerciseAnalyzing Windows LSASS Memory Dump via comsvcs.dll MiniDump Dataset2025-09-21Threat Hunting ExerciseAnalyzing Windows BITSAdmin LOLBIN Payload Download Dataset2025-09-22Threat Hunting ExerciseAnalyzing Windows Registry Run Key + Startup Folder Dual Persistence Dataset2025-09-23Threat Hunting ExerciseAnalyzing Windows PrintNightmare Print Spooler Exploitation Dataset2025-09-24Threat Hunting ExerciseAnalyzing Windows COM Hijacking Persistence Dataset2025-09-25Threat Hunting ExerciseAnalyzing Windows Volume Shadow Copy Deletion Pre-Ransomware Dataset2025-09-26Threat Hunting ExerciseAnalyzing Windows AMSI Bypass via PowerShell Reflection Dataset2025-09-27Threat Hunting ExerciseAnalyzing Linux Bash History Clearing & Auth Log Tampering Dataset2025-09-28Threat Hunting ExerciseAnalyzing Linux Loadable Kernel Module (LKM) Rootkit Dataset2025-09-29Threat Hunting ExerciseAnalyzing Linux Docker Socket Mount Container Escape Dataset2025-09-30Threat Hunting ExerciseAnalyzing Linux Cron Job + Web Shell Persistence Combo Dataset2025-10-01Threat Hunting ExerciseAnalyzing Linux Sudoers File Modification Privilege Escalation Dataset2025-10-02Threat Hunting ExerciseAnalyzing Linux SSH Port-Knocking Covert C2 Channel Dataset2025-10-03Threat Hunting ExerciseAnalyzing Linux Fileless Execution via memfd_create Dataset2025-10-04Threat Hunting ExerciseAnalyzing Firewall Internal Port Scan Reconnaissance Sweep Dataset2025-10-05Threat Hunting ExerciseAnalyzing Firewall ICMP Tunnel Data Exfiltration Dataset2025-10-06Threat Hunting ExerciseAnalyzing Firewall Unauthorized Rule Change Audit Anomaly Dataset2025-10-07Threat Hunting ExerciseAnalyzing Windows Rubeus OverPassTheHash Ticket Renewal Dataset2025-10-08Threat Hunting ExerciseAnalyzing Windows Unconstrained Kerberos Delegation Abuse Dataset2025-10-09Threat Hunting ExerciseAnalyzing Windows NTDS.dit Dumping via Ntdsutil Dataset2025-10-10Threat Hunting ExerciseAnalyzing Windows MSHTA LOLBIN Remote Payload Execution Dataset2025-10-11Threat Hunting ExerciseAnalyzing Windows Token Impersonation SeDebugPrivilege Dataset2025-10-12Threat Hunting ExerciseAnalyzing Windows GPO Abuse Malicious Scheduled Task Push Dataset2025-10-13Threat Hunting ExerciseAnalyzing Windows DLL Sideloading Signed Binary Proxy Execution Dataset2025-10-14Threat Hunting ExerciseAnalyzing Windows Certutil LOLBIN Payload Download Encode Dataset2025-10-15Threat Hunting ExerciseAnalyzing Linux Setuid Binary Abuse Privilege Escalation Dataset2025-10-16Threat Hunting ExerciseAnalyzing Linux Capabilities Abuse Setcap Privilege Escalation Dataset2025-10-17Threat Hunting ExerciseAnalyzing Linux Reverse Shell Netcat Mkfifo Dataset2025-10-18Threat Hunting ExerciseAnalyzing Linux XMRig Cryptomining Malware Dataset2025-10-19Threat Hunting ExerciseAnalyzing Linux Log4Shell JNDI WebShell Dataset2025-10-20Threat Hunting ExerciseAnalyzing Linux SSH Brute Force Credential Stuffing Dataset2025-10-21Threat Hunting ExerciseAnalyzing Firewall DNS Tunnel Port53 Exfiltration Dataset2025-10-22Threat Hunting ExerciseAnalyzing Firewall TOR Exit Node Outbound Connection Dataset2025-10-23Threat Hunting ExerciseAnalyzing Firewall VPN Proxy Rotation Geofence Bypass Dataset2025-10-24Threat Hunting ExerciseAnalyzing Firewall Cloud Storage IP Range Exfiltration Dataset2025-10-25Threat Hunting ExerciseAnalyzing IDS Log4j JNDI Exploitation Signature Dataset2025-10-26Threat Hunting ExerciseAnalyzing IDS SQLMap Automated Injection Signature Dataset2025-10-27Threat Hunting ExerciseAnalyzing Firewall Outbound SMTP Relay Spam Botnet Dataset2025-10-28Threat Hunting ExerciseAnalyzing Firewall SMB Null Session Enumeration Dataset2025-10-29Threat Hunting ExerciseAnalyzing Firewall Low-and-Slow Idle-Session C2 Beacon Dataset2025-10-30Threat Hunting ExerciseAnalyzing IDS Cobalt Strike Malleable C2 Jitter Beacon Dataset2025-10-31Threat Hunting ExerciseAnalyzing IDS Web Shell Upload File Extension Signature Dataset2025-11-01Threat Hunting ExerciseAnalyzing IDS Self-Signed Certificate JA3S Fingerprint C2 Dataset2025-11-02Threat Hunting ExerciseAnalyzing Proxy DNS-over-HTTPS Exfiltration Bypass Dataset2025-11-03Threat Hunting ExerciseAnalyzing Proxy Malicious Browser Extension Data Exfiltration Dataset2025-11-04Threat Hunting ExerciseAnalyzing Windows Kerberos Silver Ticket Forgery Dataset2025-11-05Threat Hunting ExerciseAnalyzing Windows LSASS Direct Syscall EDR Evasion Dataset2025-11-06Threat Hunting ExerciseAnalyzing Windows BYOVD Malicious Kernel Driver Loading Dataset2025-11-07Threat Hunting ExerciseAnalyzing Windows Shadow Credentials msDS-KeyCredentialLink Abuse Dataset2025-11-08Threat Hunting ExerciseAnalyzing Windows RDP Session Hijacking Tscon Dataset2025-11-09Threat Hunting ExerciseAnalyzing Linux Systemd Service Unit Persistence Dataset2025-11-10Threat Hunting ExerciseAnalyzing Linux Init.d/RC.local Legacy Persistence Dataset2025-11-11Threat Hunting ExerciseAnalyzing Linux Privileged Container HostPID Escape Dataset2025-11-12Threat Hunting ExerciseAnalyzing Linux Auditd Rule Deletion Log Tampering Dataset2025-11-13Threat Hunting ExerciseAnalyzing Linux Cron Wget/Curl Malware Downloader Staging Dataset2025-11-14Threat Hunting ExerciseAnalyzing AzureAD Conditional Access Bypass Legacy Authentication Dataset2025-11-15Threat Hunting ExerciseAnalyzing GCP Service Account Key Exfiltration Abuse Dataset2025-11-16Threat Hunting ExerciseAnalyzing Email HTML Smuggling Phishing Attachment Delivery Dataset2025-11-17Threat Hunting ExerciseAnalyzing DNS Zone Transfer AXFR Reconnaissance Dataset2025-11-18