September 28, 2026

The GATES Method: when a hunt becomes a detection

GATES is a five-gate checklist for turning threat hunt findings into detections. Pressure-tested against 350 hunts and shipping as a /skill in the ATHF repo.

Read More
September 24, 2026

When Your Insider Risk Program is Put to the Test

A fully-mature security stack missed real insider risk activity during a restructuring, until one Nebulock hunt caught data exfiltration happening in real-time.

Read More
September 15, 2026

Your Network's Adversary Might Be Poor Hygiene

Threat hunting isn't only for targeting adversaries. Learn how to use network telemetry (Zeek, Defender for Endpoint) to hunt cleartext credentials, Kerberos RC4, and forgotten devices.

Read More

Hunt-first security

For what your alerts can't see.

Get a Demo