SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsStop waiting for alerts. Learn how to launch a proactive threat-hunting program with clear hypotheses, strong telemetry, repeatable workflows, and outcomes that improve detections even when no threat is found.

If your security team is still waiting for an alert before it starts investigating, you’re playing the reactive game. Threat hunting flips that script — it puts humans in the loop to proactively find threats tools miss and to continually harden and improve your environment with every iteration.
A lot of people and companies have tried to create a definition for threat hunting. At its core, cyber threat hunting is a human‑led, proactive effort to discover malicious activity that slips past existing controls across endpoints, networks, cloud, identity systems, etc. It’s not an alert queue with a different name, not a one‑off Indicator of Compromise (IoC) search, and not red‑, purple‑, or pen‑testing. Threat hunting is a recurring discipline that results in a reduction of dwell time and closes visibility gaps aligned to your business risks. Overall, it is aimed to help improve your security capabilities. Two practical implications flow from the above definition:
Frameworks help you standardize a repeatable cycle, from hypothesis to validation, so you’re not reinventing the wheel with every hunt. No single framework is “the one.” Start from one, borrow the bits you need from others, and evolve it for your environment.
You can’t hunt everywhere at once. Scope hunts based on business risk and threat intelligence, focusing first where compromise hurts most and visibility is weakest — crown jewels, internet‑facing systems, and admin/privileged tiers — while documenting explicit exclusions for fragile or legacy systems. This means you need to know and understand your environment.
Hunting is a team sport. Define clear roles — hunters, SOC analysts, incident responders, intel analysts, etc. — and commit to continuous skill growth in query languages (KQL/SPL), Python/PowerShell, malware analysis, behavioral analytics, and CTI interpretation. Hunting teams can be structured in-house, as a hybrid model, or fully outsourced—each with trade-offs in cost, environmental context, and access to specialized expertise. Outsourcing the threat hunting capability can be a viable option for some organizations. Many organizations struggle with a lack of resources, rapid evolution of threats, and specialized knowledge and skills that are required for threat hunting. That said, external teams typically need more time to build the deep contextual knowledge an internal team has by default. • External Hunt Team
• Dedicated Hunt Team
• Combined/Hybrid Team
• Periodic Hunt Teams
A process for conducting threat hunting needs to be clearly defined. Based on the framework selected there will be some specifics in the process. Overall, the threat hunting process typically consists of the following steps:
Building effective threat hunting hypotheses involves creating actionable, testable statements based on threat intelligence and environmental context to guide your investigations. We need to understand what adversaries would do. External intelligence includes any type of open-source intelligence (OSINT) that threat hunters can use to identify threats in their environment. This can include:
A good hypothesis should be framed as a question or statement that helps identify threats and gather information about your environment, and that can be proven true or false. For example: “If an attacker has gained initial access through phishing, we might see unusual PowerShell execution in user endpoints.”
Once hypotheses are established, the next step is to determine what evidence is needed to validate or refute them. This involves:
• Identifying which logs, telemetry, and alerts can provide relevant information. For example:
• Prioritizing sources: Focus on high-value data that is most likely to confirm or deny the hypothesis. • Understanding data availability and gaps: Document what data is accessible and where visibility is lacking. This helps refine the scope of the hunt and identify areas for improvement in monitoring.
The data must be collected, obtained, and prepared for analysis. Sometimes data will need to be transformed to be useable:
This step involves analyzing the prepared data to validate the hypothesis:
This phase often requires both automated detection and human-driven analysis to uncover subtle indicators of compromise.
Once findings are confirmed, you can take further action, such as:
A hunt is only as good as your data. Prioritize complete, time‑bound, accessible telemetry with sufficient retention: EDR/XDR process trees, Sysmon, DNS/Proxy logs, NetFlow, AD/cloud auth, and CTI. Choose analysis platforms your team can query fluently (ELK, Splunk, Velociraptor) and integrate SOAR for orchestration.
Turn hunting into an organizational capability by capturing hypotheses, evidence, detection logic, and improvements to your processes. Track metrics such as ATT&CK coverage delta, hunt‑to‑detection ratio, hunt frequency, visibility fixes, dwell‑time impact, and false‑positive reduction.
Use HMM to benchmark where you are and to prioritize what’s next: HMM0 (Initial), HMM1 (Minimal), HMM2 (Procedural), HMM3 (Innovative), HMM4 (Leading/Automated). Don’t try to jump from HMM0 to HMM3 in a quarter — first fix telemetry (HMM1 → HMM2), then invest in new analysis techniques and automation.
Phase 1: Establish the foundation
Phase 2: Execute and codify
Phase 3: Institutionalize and expand
Getting from alerts to adversaries doesn't require a mature program on day one. It requires a first hunt, a documented outcome, and a habit of repeating the cycle. Start with Phase 1 this quarter: validate your telemetry, write your first hypotheses, and set the metrics you'll track. Everything else in this guide compounds from there.


Jan D’Herdt is a SANS Certified Instructor teaching LDR512 and SEC566. With experience across Deloitte, IBM, and UCB, he helps organizations implement and transform the CISO organization, and align cybersecurity with governance and business risk.
Read more about Jan D'Herdt