# Threat Hunting & Intel

Cybersecurity discipline involving threat hunting and cyber threat intelligence.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs

DevFeed: [A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs](<https://devfeed.tech/articles/mapping-out-your-unknown-a-threat-hunter-s-guide-to-github-30894.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github/>)

Author: Julie Agnes Sparks, Juvenal Araujo

Published: 2026-09-16T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [personal access token](<https://devfeed.tech/topics/personal-access-token.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [github](<https://devfeed.tech/tags/github.md>), [logging](<https://devfeed.tech/tags/logging.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

This article examines threats targeting GitHub organizations, including compromised accounts, personal access tokens, OAuth tokens, leaked secrets, phishing, and malicious extensions or OAuth apps. It describes GitHub audit-log queries and behaviors that can help detect account compromise, reconnaissance, and source-code exfiltration.

### Source excerpt

In this post, we walk through different threats to GitHub and how to detect them.

## Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

DevFeed: [Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time](<https://devfeed.tech/articles/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time-8414.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc/>)

Author: Jessica (Bair) Oppenheimer

Published: 2026-09-07T15:00:58Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

Cisco describes its work protecting the Black Hat USA 2026 network alongside NOC leaders and technology partners. The team combined security telemetry and workflows to support visibility, detection engineering, threat hunting, malware analysis, AI protection, and Agentic SOC development.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

## How iFood built its agentic security platform on ClickHouse Cloud

DevFeed: [How iFood built its agentic security platform on ClickHouse Cloud](<https://devfeed.tech/articles/how-ifood-built-its-agentic-security-platform-on-clickhouse-cloud-5309.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/ifood-agentic-security-platform>)

Author: ClickHouse

Published: 2026-08-12T15:29:05Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Security](<https://devfeed.tech/topics/security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [data](<https://devfeed.tech/topics/data.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [aws](<https://devfeed.tech/tags/aws.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cost](<https://devfeed.tech/tags/cost.md>), [data](<https://devfeed.tech/tags/data.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

iFood rebuilt its in-house security platform on ClickHouse Cloud to handle high-volume log ingestion, long-term retention, and rapid incident response. Compared with its earlier Databricks-based approach, the platform delivered 9-16x faster queries at 40-50% lower cost, near real-time data freshness, and agentic threat-hunting workflows that reduced work from about a week to roughly two hours.

### Source excerpt

iFood rebuilt its in-house security platform on ClickHouse Cloud, getting 9-16x faster queries at 40-50% of the cost and unlocking agentic threat hunts that cut a week of analyst work down to two hours.

## Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM

DevFeed: [Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM](<https://devfeed.tech/articles/automatically-enrich-security-logs-with-mitre-att-ck-context-before-they-reach-your-siem-2291.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/mitre-attack-enrichment-packs-observability-pipelines/>)

Author: Danielle Park

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Observability Pipelines uses MITRE ATT&CK Enrichment Packs to automatically map security logs and events to common attacker tactics and techniques before they reach a SIEM, data lake, or archive. It describes the initial packs for Okta, Palo Alto, FortiGate, and AWS WAF, covering identity, firewall, network, and web security activity.

### Source excerpt

Learn how Observability Pipelines enriches security logs with MITRE ATT&CK tactics and techniques before routing them to your SIEM or storage destination.

## LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

DevFeed: [LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine](<https://devfeed.tech/articles/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine-8316.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukraine/>)

Author: LABScon

Published: 2026-06-02T13:00:58Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [LABScon](<https://devfeed.tech/topics/labscon.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [labscon](<https://devfeed.tech/tags/labscon.md>), [labscon25](<https://devfeed.tech/tags/labscon25.md>), [malware](<https://devfeed.tech/tags/malware.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [research](<https://devfeed.tech/tags/research.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

ESET researchers present technical evidence that Gamaredon facilitated Turla's access to high-value Ukrainian targets between February and June 2025. The presentation examines their operational collaboration, the deployment of Turla's Kazuar backdoor, and the implications for defenders tracking Russian cyberespionage.

### Source excerpt

ESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups.

## Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity

DevFeed: [Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity](<https://devfeed.tech/articles/locks-socs-and-a-cat-in-a-box-what-schrodinger-can-teach-us-about-cybersecurity-8335.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/locks-socs-cat-box-what-schrodinger-can-teach-us-about-cybersecurity/>)

Author: Steven Connolly

Published: 2025-12-11T10:00:00Z

Content type: opinion

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [marketing](<https://devfeed.tech/tags/marketing.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

The article uses Schrödinger's cat as an analogy for the uncertainty facing organisations that lack visibility into their security environment. It argues that organisations should assume threats may already be present and strengthen their cybersecurity strategy through internal threat hunting, monitoring, and appropriate security tools.

### Source excerpt

If you don't look inside your environment, you can't know its true state - and attackers count on that

## Threat Hunting with Kubernetes Audit Logs - Part 2

DevFeed: [Threat Hunting with Kubernetes Audit Logs - Part 2](<https://devfeed.tech/articles/threat-hunting-with-kubernetes-audit-logs-part-2-15923.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/threat-hunting-with-kubernetes-audit-logs-part-2>)

Author: Ramesh Ramani

Published: 2021-08-17T19:00:00Z

Content type: tutorial

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [events](<https://devfeed.tech/tags/events.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [logs](<https://devfeed.tech/tags/logs.md>), [policy](<https://devfeed.tech/tags/policy.md>)

### AI overview

This tutorial explains how to use Kubernetes audit logs with the MITRE ATT&CK framework and a Kubernetes threat matrix to hunt for attackers. It develops hypotheses and example queries, including an investigation of repeated failed pod exec attempts by an anomalous user.

### Source excerpt

Using the MITRE ATT&CK® Framework to hunt for attackers

## Threat Hunting with Kubernetes Audit Logs

DevFeed: [Threat Hunting with Kubernetes Audit Logs](<https://devfeed.tech/articles/threat-hunting-with-kubernetes-audit-logs-15922.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/threat-hunting-with-kubernetes-audit-logs>)

Author: Ramesh Ramani

Published: 2021-08-03T19:00:00Z

Content type: tutorial

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon Elastic Kubernetes Service](<https://devfeed.tech/topics/amazon-elastic-kubernetes-service.md>), [Operator Lifecycle Manager](<https://devfeed.tech/topics/olm.md>)

Tags: [api-server](<https://devfeed.tech/tags/api-server.md>), [audit](<https://devfeed.tech/tags/audit.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [aws](<https://devfeed.tech/tags/aws.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-clusters](<https://devfeed.tech/tags/kubernetes-clusters.md>), [logs](<https://devfeed.tech/tags/logs.md>)

### AI overview

This tutorial introduces Kubernetes audit logs and explains how they can provide an audit trail of API calls for threat hunting. It outlines a process for understanding the environment, forming and testing hypotheses, identifying anomalous behavior, establishing repeatable patterns, and enriching detection pipelines.

### Source excerpt

Analyzing Kubernetes audit logs to look for potential threats

## Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion

DevFeed: [Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion](<https://devfeed.tech/articles/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-20500.md>)

Original publisher: [Read original article](<https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/>)

Author: bohops

Published: 2021-03-16T04:08:58Z

Content type: article

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [.NET](<https://devfeed.tech/topics/net.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [logging](<https://devfeed.tech/tags/logging.md>), [net](<https://devfeed.tech/tags/net.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This article examines how .NET CLR Usage Logs can help defenders detect and investigate .NET execution, including assembly injection into process memory. It describes how the CLR creates Usage Log files and discusses tampering techniques intended to evade endpoint detection, along with monitoring opportunities for identifying that tampering.

### Source excerpt

Introduction In recent years, there have been numerous published techniques for evading endpoint security solutions and sources such as A/V, EDR and logging facilities. The methods deployed to achieve the desired result usually differ in sophistication and implementation, however, effectiveness is usually the end goal (of course, with thoughtful consideration of potential tradeoffs). Defenders can [...]