Advanced Cyber Threat Intelligence and Hunting Detect APTs and zero-day attacks using CTI, behavioral analytics, and AI… (Gianluca Tiepolo, Dan Sorensen)(Z-Library)
ai
No Description
11
Views
0
Downloads
0.00
Total Donations
Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Page
1
(This page has no text content)
Page
2
Advanced Cyber Threat Intelligence and Hunting Detect APTs and zero-day attacks using CTI, behavioral analytics, and AI techniques Gianluca Tiepolo Dan Sorensen
Page
3
Advanced Cyber Threat Intelligence and Hunting Copyright © 2026 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the authors, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Portfolio Director: Vijin Boricha Relationship Lead: Anindya Sil Program Manager: Ankita Thakur Project Manager: Gandhali Raut Content Engineer: Tazeen Shaikh Technical Editors: Aysha Nadeem, Nithik Cheruvakodan, and Riya Agarwal Indexer: Hemangini Bari Copyediting and Proofreading: Tazeen Shaikh Production Designer: Salma Patel Growth Lead: Ankita Thakur First published: April 2026 Production reference: 1300426 Published by Packt Publishing Ltd. Grosvenor House 11 St Paul's Square Birmingham B3 1RB, UK. ISBN 978-1-80638-039-8 www.packtpub.com
Page
4
Contributors About the authors Gianluca Tiepolo is a passionate cybersecurity researcher who specializes in cyber threat intelligence within the telecommunications industry. Over the past fifteen years, his consulting experience has encompassed forensic analysis, threat hunting, incident response, and cyber threat intelligence for numerous organizations, including several Fortune 100 companies. Leveraging years of hands-on experience, Gianluca has had the privilege of working with some of the leading global telcos including Verizon, Deutsche Telekom, T- Mobile and Telecom Italia. He holds a BSc degree in Computer Science and an MSc in Information Security, as well as several security related certifications. He is also the author of Getting Started with RethinkDB and iOS Forensics for Investigators, from Packt Publishing. This book would not have been possible without the support, patience and expertise of a remarkable group of people. First and foremost, I would like to thank the entire team at Packt Publishing. A special thanks goes to my content engineer, Tazeen Shaikh, for her incredible patience and guidance throughout this journey. Her ability to navigate both the technical and editorial aspects of this project made a real difference. I am also deeply grateful to Gandhali Raut, our project manager, and to Anindya Sil, who, from the very beginning, helped shape the direction of this book and worked tirelessly to keep everything moving forward. A sincere thank you as well to Dan Sorensen, my co-author, whose experience and perspective have significantly strengthened this work. I am hugely indebted to Maria Saleri, who served as a technical reviewer for this book. This project would simply not have been possible without her. Beyond being a passionate researcher, she is also a great friend, and I feel incredibly fortunate to have her in my life. I would also like to thank the friends and colleagues who generously dedicated their time to read drafts of this book and provide thoughtful feedback. In particular, I am grateful to Marco Ippolito, Rémi Arsene, Andrea Rapisarda, Davide Gambino and Veronica Tecan for their insights and support. Finally, I want to express my deep appreciation to the broader cybersecurity research community. This book is, in many ways, the result of countless hours of research, shared knowledge, and open collaboration. In particular, I would like to thank: Alex Teixeira, Andrea Pierini, Andrea Varischio, Benjamin Delpy, Certis Foster, Charlie Bromberg, Clément Labro, Dominic Chell, Elad Shamir, Florian Roth, Joseph Slowik, Kevin Beaumont, Maurice Fielenback, Oleg Skulking, Oliver Lyak, Romain Bentz and Valdemar Carøe. Some of these individuals are former colleagues, others are researchers whose work has had a profound influence on my own. To all of you—and to everyone who shares knowledge, publishes research, and contributes to the community—thank you for helping make our (digital) world more secure!
Page
5
Dan Sorensen is a cybersecurity and AI governance leader with over 23 years of experience in cyber threat intelligence, threat hunting, incident response, and security engineering across aerospace, defense, healthcare, and critical infrastructure. He is the founder and principal of Nexus Security Advisors Ltd., where he serves as a fractional CISO and AI governance advisor to enterprises and U.S. government contractors operating in highly regulated environments. A U.S. Air Force and Air National Guard veteran, his work focuses on AI-driven defense, operational threat intelligence, and the protection of mission-critical systems against advanced adversaries. Dan is a contributing author to The AI Mindset: Thriving Within Civilization's Next Big Disruption (2024) and an editor of the Geneva Manual on Cyber Threat Intelligence Sharing: Security Policy Implications and Recommendations (2025), aligning operational CTI practices with emerging policy and regulatory frameworks. He is a Forbes Technology Council and Fast Company Executive Board contributor, with more than 35 published articles, and a core team member of the OWASP AI Exchange, helping shape global AI security guidance referenced by the EU AI Act. He holds an MA in Strategic Intelligence and a BA in Middle Eastern Studies and Linguistics, is a graduate of the Defense Language Institute, and is completing a PhD in Cybersecurity Leadership at Capitol Technology University. In addition to English, Dan works in Spanish and Hebrew, reflecting his belief that effective threat intelligence is fundamentally multilingual. He lives in Denver with his family.
Page
6
About the reviewers Maria Saleri is a cyber security analyst on the Cyber Threat Intelligence team at TIM, Italy's largest telecommunications operator, where she tracks adversary activity and produces intelligence to support detection and response across the enterprise. Her work focuses on threat analysis and security operations, with particular attention to detecting and investigating advanced threats targeting large-scale infrastructure. Maria holds a BSc and an MSc in Computer Engineering, both from the University of Brescia. Seetal Patel is a seasoned cybersecurity leader specializing in AI security and identity security, with over two decades of experience driving enterprise transformation across complex digital landscapes. Known for blending deep technical expertise with strategic foresight, he is a trusted advisor to global organizations navigating the convergence of IT, OT, and cloud-first architectures. He has also contributed to the NIST NCCoE Zero Trust initiative. After a distinguished nine-year tenure at Palo Alto Networks—where he led advanced engineering, consulting, and security architecture initiatives—Seetal now serves in a senior role at Cato Networks. His work focuses on empowering enterprise clients through secure platform design, strategic advisory, and operational excellence in SASE and AI security transformations. Outside of work, Seetal enjoys cricket and has a lifelong fascination with military aviation.
Page
7
(This page has no text content)
Page
8
Table of Contents Preface xxvii Free benefits with your book ......................................................................................................... xxxii Part 1: Foundations of Cyber Threat Intelligence 1 Chapter 1: Revisiting CTI for Advanced Threat Hunting 3 Defining CTI ........................................................................................................................................ 4 Strategic, operational, and tactical CTI • 4 The Pyramid of Pain • 5 Low pain indicators • 5 Medium pain indicators • 6 High pain indicators • 6 IOCs vs. TTPs ....................................................................................................................................... 6 Defining cyber threats ......................................................................................................................... 7 Known threats • 8 Unknown threats • 9 The pitfalls of overfocusing on known threats .................................................................................... 9 The intelligence cycle ......................................................................................................................... 11 The proactive workflow • 13 Introducing threat hunting • 13 Key frameworks for intrusion analysis ............................................................................................... 15 Practical exercise – mapping CTI to MITRE ATT&CK for hypothesis generation • 16 Scenario • 16 Sample report • 16 Tasks • 17 Summary ............................................................................................................................................ 17 Chapter 2: Understanding APTs – Actors, Motivations, and TTPs 19 Introducing threat actors .................................................................................................................. 19 Defining actor types • 20 Understanding advanced persistent threats • 20 A history of APTs ................................................................................................................................ 22 The case of Moonlight Maze (1996-1998) • 22
Page
9
Stuxnet (2010) • 22 The APT1 report (2013) • 23 The modern APT • 24 Understanding APT intent, capabilities, and common modus operandi ............................................ 25 Intent and motivations • 26 Capabilities and modus operandi • 26 Offensive development and capabilities • 26 Infrastructure and logistics • 27 Lateral movement and persistence • 27 Data exfiltration • 27 Evasion and anti-forensics • 27 Cloud, Edge devices and IoT exploitation • 28 Artificial intelligence and automation • 28 Using the Kill Chain for intrusion analysis ........................................................................................ 28 Dissecting the Cyber Kill Chain • 29 Reconnaissance • 29 Weaponization • 29 Delivery • 30 Exploitation • 30 Installation • 30 Command and Control (C2) • 31 Actions on Objectives • 31 Practical use case: Analyzing an APT28 intrusion • 31 Campaign summary • 31 Campaign analysis • 32 Summary ........................................................................................................................................... 34 Further reading ................................................................................................................................. 34 Chapter 3: Deep Dive – CTI Collection and Enrichment for APTs 37 CTI collection in the security operations workflow ........................................................................... 38 Traditional data collection • 38 Open-source intelligence (OSINT) • 39 Commercial and vendor intelligence feeds • 39 Internal sources • 39 Threat intelligence platforms • 40 The evolution beyond basic threat feeds • 40 Enrichment: The alchemy of CTI ....................................................................................................... 41 Enrichment tools • 42 Table of Contents viii
Page
10
Automation workflow • 43 Analysis and analytic pivoting ........................................................................................................... 44 Introducing the Diamond Model • 45 Mapping the attack lifecycle with MITRE ATT&CK • 47 Adversary hunting ............................................................................................................................. 47 Tracking threat actor infrastructure over time • 48 Infrastructure overlap • 48 Passive DNS • 49 WHOIS analysis • 50 IP address analysis • 51 Certificate analysis • 51 JARM fingerprints • 52 Response headers and content • 53 Tracking APTs across multiple campaigns • 54 Static indicator analysis • 54 Tracking malware families with imphash • 55 Tracking malware evolution using fuzzy hashing • 55 Malware metadata • 56 Practical exercise • 56 Tracking adversary infrastructure with VirusTotal • 57 Tracking campaigns with Shodan and Censys • 58 Expanding the campaign scope with pDNS • 58 Tying it all together: from indicators to intelligence • 59 Creating APT profiles ........................................................................................................................ 60 Core components of a threat profile • 60 Intent and motivation • 60 Sophistication and capability • 61 Victimology • 61 Unmasking the persona • 61 Linguistic footprints • 62 Cultural and geopolitical indicators • 62 OPSEC and human error • 63 Operational and tactical profiling • 63 Analyzing timestamps • 63 Identifying infrastructure • 64 Establishing the adversary's playbook • 65 Summary ........................................................................................................................................... 66 Further reading ................................................................................................................................. 66 ix Table of Contents
Page
11
Part 2: Advanced Threat Hunting 69 Chapter 4: Core Principles of Proactive Threat Hunting 71 Introducing threat hunting ............................................................................................................... 72 What is a hypothesis? • 72 Why automated defenses miss APTs and zero-days • 73 The threat hunter workflow • 74 Translating intelligence into action ................................................................................................... 75 Creating hunt queries • 75 Detection engineering ....................................................................................................................... 77 Translating CTI into actionable Sigma rules • 78 Practical use case: Detecting DNS tunneling • 79 Sigma temporal correlations • 80 Crafting and applying YARA rules • 81 Practical use case: Detecting STARWHALE backdoors • 81 Network detection using Snort rules • 83 Practical use case: Detecting C2 traffic through TXT records • 83 Putting it all together ........................................................................................................................ 84 Start with TTPs, not just IOCs • 84 Use contextual strings in YARA • 85 Think in sequences for sigma rules • 85 Apply thresholds and rarity • 85 Write for evasion resistance • 85 Use multi-layer coverage • 85 Maintain flexibility and expiry • 85 Don't forget the adversary • 85 Summary ........................................................................................................................................... 86 Chapter 5: Understanding Data Sources for Threat Hunting 87 Tools and technologies for telemetry engineering ............................................................................. 87 The hunt-driven data model • 88 Designing a collection strategy • 89 Data enrichment • 90 Endpoint telemetry ........................................................................................................................... 91 Uncovering adversary actions on the host • 92 Process creation and termination • 93 Network connections • 93 Table of Contents x
Page
12
Filesystem events • 94 Registry modifications • 94 Image/module load • 94 Driver load • 94 Create remote thread • 95 Raw disk access • 95 Process access • 95 Named pipe events • 95 WMI events • 96 Logon sessions • 96 Service creation/modification • 97 Refining telemetry • 97 Network telemetry ............................................................................................................................ 97 Tracking adversaries across the wire • 98 Full packet capture (PCAP) • 98 Firewall logs • 98 NetFlow data • 99 DNS query logs • 99 Web proxy logs • 100 IDS/IPS alerts • 100 TLS handshake logs • 101 HTTP transaction logs • 101 Network share access logs • 102 Logs and identity telemetry ............................................................................................................. 103 Application logs • 103 Custom logs • 103 Authentication and identity telemetry • 104 Active Directory logging • 104 Active Directory audit policies • 105 Event IDs that matter • 105 Practical use case – China Chopper web shell .................................................................................. 106 The attack narrative • 107 Detection opportunities • 107 Application logs and events • 108 Host and network telemetry • 109 Hunting recipes • 109 Hunting anomalous script activity (application layer) • 110 Entropy-based body inspection • 110 xi Table of Contents
Page
13
Endpoint detection • 111 Network detection • 112 Analytical insights • 112 Summary .......................................................................................................................................... 113 Get this book'ss PDF copy, code bundle, and more ........................................................................... 114 Chapter 6: Hunting Zero-Days Through Behavioral Signatures 115 Detecting the unknown with behavioral analysis ............................................................................ 116 Detection opportunities • 116 The enterprise-scale factor • 117 Applying ML to threat hunting ......................................................................................................... 118 ML in security operations context • 118 Key concepts and terminology for hunters • 119 Feature • 119 Cardinality • 119 Bucket span • 120 Influencer • 120 Population job • 121 Anomaly score • 121 Contamination rate • 121 Practical limits and expectations • 122 Correlating crashes and instability to uncover exploitation ............................................................. 122 Why crashes matter for zero-day detection • 123 Telemetry requirements • 123 Case study: Lazarus and the Chrome renderer zero-day • 126 Detecting post-exploitation activity ................................................................................................. 127 Observable artifacts • 127 Process lineage anomalies • 128 Memory injection and code manipulation • 128 Privilege escalation and token abuse • 130 Operationalizing ML jobs with Elastic • 132 Detecting exploits and C2 channels in network telemetry ................................................................ 136 Outbound exploitation and C2 signals • 136 Inbound exploit delivery and service abuse • 137 East–west movement and data exfiltration • 137 Practical use case: Hunting zero-day exploitation in Apache Logs • 138 The scenario • 138 Step 1: Understanding the data • 138 Table of Contents xii
Page
14
Step 2: Feature engineering • 139 Step 3: Defining ML detectors • 140 Step 4: Designing the Elastic ML job • 141 Step 5: Interpreting results • 142 Operational takeaways • 142 Putting it all together ....................................................................................................................... 142 Visibility before intelligence • 143 Baselines over signatures • 143 Scale is the enemy and the weapon • 143 ML and AI are analytical amplifiers, not oracles • 143 Correlation is king • 143 History is an intelligence source • 144 Summary ......................................................................................................................................... 144 Further reading ............................................................................................................................... 144 Chapter 7: Advanced Hunting Techniques and Queries 147 Analytical techniques for human-driven threat hunting ................................................................. 148 Stack counting – reducing noise to insights • 148 Temporal correlation – finding rhythm in intrusions • 149 Feature engineering and behavioral clustering • 150 Visual analytics • 151 Box plots • 151 Sparklines • 152 From analytics to detection • 153 Practical use case – detecting C2 beaconing • 154 Scenario • 154 Dataset • 154 Step 1 – reducing noise through stack counting • 154 Step 2 – measuring temporal regularity • 155 Step 3 – correlating across features • 155 Step 4 – turning insight into detection • 156 Hunting with ES|QL • 156 Building a box plot visualization • 158 Key takeaways • 158 Mastering ephemeral baselining ..................................................................................................... 158 Operationalizing ephemeral baselines • 159 Building the baseline • 160 Detecting new activity • 160 xiii Table of Contents
Page
15
Maintenance and lifespan • 160 Platform considerations • 160 Practical use case – detecting LOLBAS abuse • 161 Dataset • 162 Building the LOLBAS baseline • 162 Detecting the outlier • 163 Deception as a hunting strategy ...................................................................................................... 164 Defining deception goals • 165 The phenomenon of read teaming • 165 Building deceptive artifacts • 166 Planning deception operations • 167 Step 1 – governance and constraints • 167 Step 2 – define goals • 167 Step 3 – threat modeling and adversary profiling • 168 Step 4 – pattern analysis • 168 Step 5 – design deception assets • 168 Step 6 – instrumentation and telemetry • 169 Step 7 – deployment • 169 Step 8 – detection playbooks • 170 Adversary emulation for hunting validation ................................................................................... 170 From CTI to emulation plan • 172 Scaling emulation – from atomic tests to continuous validation • 172 Summary .......................................................................................................................................... 173 Further reading ................................................................................................................................ 174 Part 3: Practical APT Hunting Across the Cyber Kill Chain 175 Chapter 8: Hunting Delivery and Initial Access 177 The strategic evolution of initial access ........................................................................................... 178 The role of Delivery and Initial Access in an intrusion • 179 Common attack vectors • 180 Phishing and social engineering ...................................................................................................... 180 The Email Threat Vector • 181 SPF architecture and the forwarding blind spot • 181 DMARC policy inheritance and subdomain exploitation • 182 De-anonymizing the sender: X-Originating-IP • 182 The decoupled Reply-To attack • 183 Homoglyphs, typosquatting and zero-width evasion • 184 Table of Contents xiv
Page
16
Detection opportunities • 184 Payload delivery mechanisms and Client-Side evasion • 185 HTML smuggling • 185 The MotW bypass: ISO and IMG files • 186 LNK files and polyglots • 187 The persistence of the human factor • 187 Case study: ClickFix and the PhantomCaptcha campaign • 187 Detection opportunities • 189 The rise of identity-based attacks .................................................................................................... 190 The weaponization of Identity • 191 The industrial ecosystem: IABs and InfoStealers • 191 The evolution of Credential Attacks • 191 On-premises AD identity attacks • 192 Password spraying • 192 Tracking valid credentials usage • 194 Cloud identity attacks • 195 Understanding tokens, protocols, and the modern login flow • 195 Session hijacking • 196 Adversary-in-the-Middle (AitM) phishing • 198 OAuth consent phishing • 200 MFA exploitation and fatigue • 202 Case study: Nobelium Microsoft campaign • 203 Phase 1: The dormant account • 203 Phase 2: The OAuth pivot • 204 Phase 3: Exfiltration via EWS • 204 Phase 4: Persistence via OAuth token lifetimes • 204 Exploitation of Edge devices ............................................................................................................ 205 Understanding the attack surface • 206 Common attack vectors on public-facing devices • 206 Detection opportunities at the Edge • 207 Detecting zero-day exploitation • 207 Hunting strategies • 208 Supply chain compromise ............................................................................................................... 209 Trusted relationship abuse • 210 Software supply chain • 210 Detection strategies • 211 Uncharacteristic child processes • 211 Network anomaly – metadata mismatch • 211 xv Table of Contents
Page
17
File integrity and signature validation • 212 Summary .......................................................................................................................................... 212 Further reading ................................................................................................................................ 213 References ........................................................................................................................................ 213 Chapter 9: Hunting for Exploitation and Execution 215 The evolution of execution techniques ............................................................................................ 216 The era of binary payloads and user-driven execution • 217 The macro era • 217 The fileless era – PowerShell, WMI and in-memory execution • 218 The LOTL era • 218 The renaissance of user-driven execution via social engineering • 219 User-driven execution ..................................................................................................................... 219 Weaponized documents • 220 Macro-enabled documents • 220 Droppers and downloaders • 222 Exploitation of DDE, OLE, and COM objects in office documents • 223 Malicious attachments • 225 LNK shortcuts • 225 HTA applications • 226 JScript, VBScript, and Windows script files • 226 OneNote files with embedded objects • 227 ISO, IMG, and ZIP container formats • 228 Case study: APT29 campaign exploiting HTML smuggling • 229 Stage 1 – spear phishing • 229 Stage 2 – HTML smuggling • 229 Stage 3 – the ISO image • 229 Stage 4 – LNK shortcuts • 229 Stage 5 – post-exploitation • 230 Fileless and in-memory execution ................................................................................................... 230 PowerShell execution • 231 Download cradles • 232 Execution policy and parameter manipulation • 233 Obfuscation techniques • 234 AMSI evasion techniques • 236 Detection opportunities and hunting queries • 236 WMI-based execution • 238 Adversary use of WMI • 239 Table of Contents xvi
Page
18
Detection opportunities • 240 Loaders, shellcode, and memory injection • 241 Shellcode injection • 242 Reflective DLL loading • 243 Raw in-memory PE loading • 245 .NET assembly loading • 245 Abuse of native system components ................................................................................................ 246 LOTL binaries • 246 Execution vectors • 247 Download vectors • 248 Scheduled execution • 250 Schtasks exploitation • 250 Detection opportunities • 251 Hunt queries • 252 Service-Based Execution • 253 Windows services • 253 Detection opportunities • 254 Hunt queries • 254 Summary ......................................................................................................................................... 256 Further reading ............................................................................................................................... 256 Chapter 10: Hunting for Persistence and Privilege Escalation 259 Abusing execution context and trust boundaries ............................................................................ 260 Introducing Privilege Escalation • 260 Process Injection • 261 Detection opportunities • 263 DLL Hijacking • 263 UAC bypass • 264 Hunting for Privilege Escalation • 265 Detecting cross-process interactions • 265 Detecting integrity level transitions • 267 Detecting process identity mismatches • 267 Hunting with machine learning • 268 Redirecting legitimate execution for persistence ............................................................................. 269 Boot, autostart, and registry-based persistence • 269 Registry run keys and startup folders • 269 Winlogon helper and Userinit persistence • 270 COM hijacking • 271 xvii Table of Contents
Page
19
Detection opportunities • 272 Windows Services and Scheduled Tasks • 274 Service-based persistence • 274 Scheduled task persistence • 275 Detection opportunities • 275 WMI event subscription persistence • 277 Detection opportunities • 277 Office application persistence • 278 Office add-ins • 278 Office template macros • 279 Malicious Outlook macros • 281 Identity-based privilege escalation and credential access ............................................................... 282 Access token manipulation • 283 Token Impersonation/Theft (T1134.001) • 283 Create Process with Token (T1134.002) • 284 Make and Impersonate Token (T1134.003) • 284 Detection opportunities • 285 NTLM exploitation • 286 Local NTLM relay and Potato attacks • 286 Forced NTLM authentication • 287 Credential Dumping • 290 LSASS dump • 291 Registry hive dump • 294 Modern Windows protections against Credential Dumping • 296 LSA protection (PPL) • 296 Virtualization-based security (VBS) • 297 HVCI • 297 Credential Guard • 298 APT tradecraft in hardened Windows environments • 300 Detection opportunities • 301 Summary ......................................................................................................................................... 302 Further reading ............................................................................................................................... 303 Chapter 11: Hunting for Lateral Movement and Discovery 305 Lateral Movement via Remote Services ........................................................................................... 306 Authentication exploitation • 307 NTLM and Pass-the-Hash • 307 Kerberos and Pass-the-Ticket • 309 Table of Contents xviii
Page
20
Overpass-the-Hash • 311 Remote Service exploitation • 312 Remote Service abuse over SMB • 313 Remote Service abuse over WMI/DCOM • 316 Remote Service abuse over WinRM • 318 Remote service abuse over RDP • 321 Relay attacks ................................................................................................................................... 322 NTLM exploitation • 323 Forced Authentication • 325 APT tradecraft • 326 Relaying to SMB for file and resource access • 326 Relaying to SMB for Remote Code Execution • 328 Resource-Based Constrained Delegation (RBCD) via LDAP relay • 331 LDAP ACL escalation leading to domain compromise • 336 Exploiting Active Directory for Lateral Movement .......................................................................... 342 DCSync • 342 DCShadow • 345 Golden Tickets • 347 Golden SAML • 350 Post-compromise discovery ............................................................................................................ 353 Host-based discovery • 354 System information and configuration • 354 Network configuration and connectivity • 355 Process and security software enumeration • 356 User and privilege discovery • 357 Domain and identity discovery • 358 Native AD enumeration • 358 LDAP reconnaissance • 359 Graph-based analysis • 360 Detection opportunities • 361 Summary ......................................................................................................................................... 363 Further reading ............................................................................................................................... 363 Chapter 12: Hunting for Command and Control 365 Network-based C2 ........................................................................................................................... 366 Application layer protocol exploitation • 366 HTTP(S) beaconing • 367 DNS-based C2 • 373 xix Table of Contents
The above is a preview of the first 20 pages. Register to read the complete e-book.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
# Advanced Cyber Threat Intelligence and Hunting
## 【One-Line Pitch】
A practical field manual for security professionals who want to move beyond reactive IOC-chasing and build proactive threat hunting programs capable of detecting APTs and zero-day attacks through behavioral analytics, CTI-driven methodology, and structured telemetry analysis.
## 【Book Arc】
- **Opening (~0%–10%)**: Establishes the core problem—SOC teams over-rely on known IOCs (hashes, IPs) while sophisticated adversaries change infrastructure and malware variants, leaving TTPs undetected. Introduces the Pyramid of Pain concept and argues for a fundamental shift from reactive to proactive defense philosophy.
- **Early (~10%–23%)**: Covers the intelligence cycle (direction, collection, processing, analysis) as the structured backbone of CTI programs. Provides historical context through major APT case studies—Moonlight Maze, Stuxnet/Operation Olympic Games, and APT28's campaign exploiting CVE-2023-38831 and CVE-2023-23397—illustrating how TTPs evolve and persist across campaigns.
- **Early (~23%–32%)**: Dives into CTI collection and enrichment techniques, including infrastructure pivoting matrices (IP→domains, domains→ASN), static analysis methods like unique string hunting, imphashing for tracking malware families across variants, and fuzzy hashing (SSDeep, SDhash, TLSH) for identifying evolutionary relationships between samples.
- **Middle (~39%–48%)**: Transitions from hunting to detection engineering—the formal process of codifying hunt findings into persistent defensive capabilities. Distinguishes signature-based from behavioral detection across three layers (file, host, network) and shows how CTI enrichment feeds rule creation (YARA, Sigma, Suricata). Covers telemetry sources including endpoint, network (PCAP, NetFlow, DNS logs), and identity/Active Directory logging.
- **Middle (~48%–52%)**: Explores the security stack architecture—SIEM at the center (Splunk SPL, Elastic ES|QL), EDR consoles, and data lakes—emphasizing that the function matters more than the product category. Discusses network telemetry features for DNS analysis, including reputation, WHOIS context, and ASN enrichment.
## 【Key Takeaways】
- **Reactive IOC-focused defense creates a false sense of security** (Opening): Adversaries can change IPs, domains, and recompile malware weekly, making hash and IP-based detection perpetually outdated. The core TTPs—credential theft, lateral movement, persistence—remain consistent and go undetected when SOCs only chase ephemeral indicators.
- **The intelligence cycle is the operational backbone of CTI** (Early): A continuous, iterative loop (direction → collection → processing → analysis) transforms raw data into actionable intelligence. This is not a one-time procedure but a systematic methodology that improves with each cycle.
- **APT history reveals the evolution of adversary tradecraft** (Early): From Moonlight Maze (1996–1998) to Stuxnet's kinetic sabotage of Iranian centrifuges to APT28's multi-stage espionage campaigns, understanding historical TTPs helps analysts recognize patterns that persist across decades of cyber operations.
- **Imphashing is a durable fingerprint for tracking malware families** (Early): Hashing the Import Address Table (IAT) creates a stable identifier that survives minor code changes—altering a function or adding a packer changes traditional hashes but not the imphash, enabling analysts to link new variants back to known threat actors.
- **Fuzzy hashing complements cryptographic hashing for variant detection** (Early): SSDeep, SDhash, and TLSH identify structural similarities between samples, making them invaluable for clustering malware families and detecting evolution even when code is reordered or obfuscated.
- **Detection engineering crystallizes hunt findings into persistent defenses** (Middle): Without codifying hunt results into signatures and rules, findings remain ephemeral. The three-layer approach—file-based (YARA), host-based (Sigma), network-based (Suricata)—ensures lessons learned in one hunt protect against future occurrences.
- **Telemetry breadth determines hunting effectiveness** (Middle): Network telemetry (PCAP, NetFlow, DNS logs, TLS handshakes) reveals lateral movement and C2 activity invisible to endpoint-only monitoring. Identity logs (Active Directory, VPN, cloud sign-ins) provide context for detecting impossible travel and privilege escalation.
- **The security stack's function matters more than its product category** (Middle): Whether hunting in a SIEM, EDR console, or data lake, the key requirement is a central place to query and correlate telemetry from multiple sources over medium-term retention windows needed for low-and-slow APT investigations.
## 【Reading Tips】
- **Skim the historical APT case studies** (Early chapters) for context, but focus on extracting the TTP patterns and detection opportunities they illustrate—these are the reusable insights.
- **Deep-read the collection and enrichment chapters** (Early ~29%–32%): The pivoting matrix and hashing techniques (imphash, fuzzy hashing) are immediately applicable to real hunting operations.
- **Pay special attention to the detection engineering section** (Middle ~42%): The three-layer framework (file/host/network) and how CTI enrichment feeds specific rule types (YARA, Sigma, Suricata) is the practical bridge from hunting to sustained defense.
- **The telemetry chapters** (Middle ~48%) are reference material—skim for the catalog of sources and their use cases, then return when designing or evaluating your own security stack.
- **Excerpts do not cover the book's later sections** on attribution (Chapter 14) and behavioral clustering for zero-day detection (Chapter 15), which appear in the table of contents but lack substantive excerpt content.
## 【Coverage Limits】
This guide synthesizes the first ~52% of the book. Later sections on attribution challenges (technical, operational, strategic), the Admiralty System for evidence scoring, and the Time-Terrain-Behavior (TTB) framework for zero-day detection are mentioned but not covered in depth due to excerpt limitations.
##
Passage locations
Excerpt 1
................................................................................................ 471 The commoditization of offensive tools • 471 Infrastruct...
View in text
Excerpt 2
undational campaign. The case of Moonlight Maze (1996-1998) This campaign was a idx_01a6b229systematic, multi-year assault on high-valueidx_cf7380de United S...
View in text
Excerpt 3
e notorious for making minor changes to their tools—such as altering a function or adding a new packer—to create a completely different hash and evade tradit...
View in text
Excerpt 4
int, that becomesidx_c4dcc275 a Suricata rule. Chapter 5 88 Telemetry engineering is driven directly idx_e7510b00 y Priority Intelligence Requirements (PIRs)...
View in text
Recommended for You
{{#thumbnailUrl}}
{{/thumbnailUrl}}
{{^thumbnailUrl}}
{{/thumbnailUrl}}
Loading recommended books...
Failed to load, please try again later
Tip the Site
Scan the WeChat Pay or Alipay code to tip. No login required.
WeChat Pay
Alipay