Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ThreatHunting-Keywords — Awesome list of keywords and artifacts for Threat Hunting sessions | Kitploit
Tools/GitHubGitHub/mthcht/threathunting-keywords
Defensive ToolsDigital ForensicsThreat IntelligenceIncident ResponseCurated ResourcesLog Analysis
GitHubmthcht/threathunting-keywords

ThreatHunting-Keywords

Awesome list of keywords and artifacts for Threat Hunting sessions

View Repository
66977131 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

ThreatHunting-Keywords

🎯 List of keywords for ThreatHunting sessions

image

Table of Contents

  • What is Threat Hunting
    • Advantages of Threat Hunting
    • Bridging Threat Hunting With Core Services
    • Detection Maturity Level
    • Key Focus Areas for Intelligence Gathering
    • Targeted Threat Hunting process
  • Files
  • ThreatHunting-Keywords for the blueteam
  • ThreatHunting-Keywords for the redteam
  • Content of the lookup
  • Hunt wih a SIEM
    • raw logs
    • specific fields
    • speed
    • dashboard example
    • Splunk4DFIR
    • With ELK it's different
    • Other awesome lists for_detection
  • Hunt without a SIEM
    • DFIR Optimized Hunt
    • YARA Rules
  • Website
  • Expected False positives
  • SIGMA rules
  • contribute

What is Threat Hunting ?

image

Threat hunting is a proactive and iterative approach to detecting malicious activities within an organization's network or systems that may have bypassed automated security measures. Unlike reactive investigations triggered by security alerts, threat hunting is driven by threat intelligence (TI)-driven checks and hypotheses derived from systematic and opportunistic analysis. These hypotheses 💡 help hunters uncover unknown threats, potential threats, or known threats that may have evaded security detections, as well as vulnerabilities or indicators of compromise (IoCs) that automated systems might miss or exclude. The process also focuses on identifying precursors to alerts/dashboards and improving SOC/triage workflows while also contributing to shadow asset inventory management and escalates low/mid-fidelity events that require further investigation. The primary goal is to identify the tactics, techniques, and procedures (TTPs) used by threat actors, enhancing the organization’s ability to preemptively detect and mitigate potential attacks.

Advantages of Threat Hunting:

  • 🔍 Identifiy Visibility Gaps
    • Detects areas where monitoring and detection are insufficient, addressing blind spots in the network or systems to mitigate hidden threats.
  • 🛠️ Fills Detection Gaps
    • Proactively searching for anomalies, precursors, and TTPs that may not trigger alerts
  • ⚙️ Improves SOC Efficiency
    • Integrates threat hunting insights into SOC workflows to uncover events that static detections might miss. By reducing false positives and escalating overlooked events, it allows SOC analysts to focus on critical threats and refine detection logic for future use.
  • 🚀 Enhances Threat Detection and supports Continuous Improvement
    • Identifies advanced, unknown, or hidden threats that bypass automated detection systems and feeds valuable data back into SOC processes, improving tools, training, and future detection capabilities
  • 🛡️ Reduces Attack Surface
    • Discovers unmanaged or unauthorized systems, applications, and shadow IT within the network, enabling organizations to address security blind spots and reduce exposure to potential threats.

Bridging Threat Hunting With Core Services

image

Threat Hunting Lifecycle in SOC Operations

My process suggestion to organizing partially automated threat hunting sessions to maintain high-quality detection rules within a SOC

SOC_Process_Threat_Hunting_to_detection

Detection Maturity Level

image SOC teams focus on deploying high-fidelity detections across all levels of the Detection Maturity Pyramid, targeting known threats with minimal false positives. Threat hunting complements this by addressing unknown threats, advanced TTPs, and anomalies prone to high false-positive rates, bridging gaps and enhancing detection coverage beyond standard SOC capabilities.

Threat Hunting Checklist - Key Focus Areas for Intelligence Gathering

image

Targeted Threat Hunting Methodology Example

image

Ideally, each threat hunting session should have clear objectives. This flowchart provides a structured approach to guide your process, from preparation and investigation to actionable recommendations.


🎯 List of keywords for ThreatHunting sessions

Files

  • ThreatHunting-Keywords
  • Greyware tools keywords
  • Offensive tools keywords
  • Vendor's Signature keywords
  • individual tools (one csv file by tool)
  • All keywords only
  • All keywords regex only
  • All keywords regex only (better perf)
  • Powershell script to hunt in files
  • Yara Rules
  • Sigma Rules

For the blueteam:

The ThreatHunting-Keywords Lists can be valuable for Threat Hunters, SOC and CERT teams for static analysis on SIEM as it assists in identifying threat actors (or redteamers 😆) using default configurations from renowned exploitation tools in logs. It differs from IOC feeds in its enduring relevance: the keywords here have no 'expiration dates' and can detect threats years after their inclusion, they are flexible accepting wildcard and non sensitive case matches and only focused on default keywords.

Download Tool