Threat Hunting Tools
Proactive threat hunting tools for Indian SOC teams — from structured hunt planning and query libraries to lateral movement deep dives and insider threat detection. Turn reactive alert response into proactive threat discovery.
Hunt Planning
Hunt Plan Builder
Build a complete, structured hunt plan from a hypothesis. Generates hypothesis statement, data sources, indicators to look for, positive finding criteria, and escalation path.
Build hunt plan →Hunt Hypothesis Library
150+ structured hunt hypotheses organised by MITRE tactic. Each with rationale, required log sources, confidence level, and ready-to-adapt query. Filter by tactic, log source, and difficulty.
Browse hypotheses →Sigma Rule Converter
Paste any Sigma rule and convert it to SPL, KQL, or EQL instantly. Runs entirely client-side — your rules never leave your browser. Covers all common Sigma field mappings.
Convert rule →Query Libraries
SPL Hunt Query Library
60+ production-ready Splunk SPL hunt queries organised by MITRE technique. Required log sources, expected output volume, tuning guidance, and what a positive looks like.
Browse SPL queries →KQL Hunt Query Library
60+ Microsoft Sentinel and Defender Advanced Hunting KQL queries. Covers Windows endpoint, Azure AD, Office 365, and network telemetry with tuning notes.
Browse KQL queries →IOC to Hunt Query Converter
Paste a list of IOCs from any threat report. Get a complete SPL and KQL query searching for all of them across process, network, DNS, and file creation events simultaneously.
Convert IOCs →Statistical Hunting
Beacon Detection Calculator
C2 beacons have distinctive timing patterns. Understand the maths and get the exact SPL/KQL query that calculates connection interval statistics and flags beaconing behaviour across your network.
Hunt beacons →Long Tail Frequency Analyser
Find rare process executions, DNS queries, or network destinations that appear on only 1–2 hosts. Paste your data as CSV and get frequency distribution with statistical outlier flagging.
Analyse frequency →LOLBin Cluster Hunt
Individual LOLBin usage is noisy. Clusters of 3+ LOLBins from the same process in 15 minutes are near-uniquely malicious. Generate the cluster detection query for your SIEM.
Hunt clusters →Lateral Movement Deep Dives
Kerberos Attack Hunt Suite
Complete hunt suite for Kerberoasting, AS-REP Roasting, Pass-the-Ticket, and Golden/Silver Ticket attacks. SPL and KQL queries for each with what the data looks like when the attack fires.
Hunt Kerberos attacks →SMB Lateral Movement Hunt
Distinguish malicious SMB lateral movement from legitimate file sharing. Covers ADMIN$/C$ share abuse, PsExec patterns, PSEXESVC artefacts, and SMB named pipe hunting.
Hunt SMB movement →Lateral Movement Hunt Pack
WMI, DCOM, WinRM, RDP, token impersonation, and remote registry — every lateral movement technique with dedicated hunt queries, required audit settings, and what normal vs malicious looks like.
View hunt pack →Insider Threat Hunting
Insider Threat Hunt Pack
Off-hours activity, abnormal data access, bulk downloads, email forwarding rules, print and screenshot activity. Complete hunt pack for insider threat indicators with SPL and KQL queries.
View hunt pack →Data Staging & Exfil Hunt
Hunt for pre-exfiltration staging — large file copies to temp directories, ZIP creation of sensitive files, database exports, cloud storage uploads, DNS exfiltration, and email exfil patterns.
Hunt data staging →Ransomware Pre-Encryption Hunt
Catch ransomware operators before they encrypt. Hunt for shadow copy enumeration, network share discovery, credential dumping, backup server access, and mass file access patterns.
Hunt ransomware staging →