HuntPack

Turning news and threat reports into detections, alerts, and mitigating controls takes a lot of time. These HuntPacks do it in one self-contained file per threat: a threat overview and MITRE ATT&CK mapping, CQL that opens straight in your own Falcon instance, the IOCs worth searching, triage steps, and the hardening that closes the gap.

Big caveat: because these packs are automated, treat the queries as starting points, not finished detections. Validate field names and tune for false positives in your own environment before relying on anything. Your data model and noise profile will differ from mine.

hunts 156queries 1221ATT&CK 328CVEs 126latest 2026-08-05RSSView on GitHub
Hunt library · newest and recently updated

No hunts match your search.