The Ultimate Threat Hunting Checklist for Cybersecurity Pros

Threat hunting is a proactive activity executed by security operations teams, risk management personnel, and IT operations. The goal of hunting for the organization is to assess, detect, and document possible cybersecurity threats before they become active.

Security operation teams (SecOps) need to develop a consistent and repeatable process to ensure the organization continues to gain value from this important exercise. By creating a threat hunting checklist, SecOps teams have a proven strategy to gather important telemetry across the network, endpoints, zero-trust authentication logs, and end-user devices. By executing successful threat hunting internal engagements, each organization will improve their overall security posture.

What Are the Key Takeaways Regarding Threat Hunting?

Threat hunting engagements place the organization on a cybersecurity offensive path, not defensive. Resources required to execute a threat hunting detection engagement become money well-spent by the organization. Here are some important points all organizations should strive towards regarding enabling and sustaining their threat hunting strategy.

  • Understand the critical role of proactive threat hunting in strengthening network resilience.
  • Discover key components and strategies essential for effective threat hunting.
  • Learn how to implement data collection and analysis tools for comprehensive threat detection.
  • Explore the deployment of advanced detection tools like EDR and IDS.
  • Adapt to the changing threat landscape with continuous strategy improvements.

Understanding the Threat Hunting Checklist

SecOps teams determined to discover the threat against their organization start with using hunting as the foundation for an efficient threat detection strategy.

Threat hunting exercises help an organization discover vulnerabilities, indicators of compromise (IoC), human error in configuration management, and inconsistency in remediation of critical assets. Discovering IoCs is critical for organizations because this shows possible air gaps in the threat detection strategy.

Importance of Proactive Security Threat Hunting

The threat from cybersecurity adversaries changes continuously. Hackers leveraging adversarial AI tools for email phishing, denial-of-service (DoS) attacks, and browser session hijacking have become more common. These AI tools help hackers automate their various attack vectors by increasing their velocity based on the success and failure of previous attacks.

AI-powered hunting tools have become very common with SecOps to help counter the hacker’s use of similar exploitation capabilities. SecOps teams also have turned to AI to assist with more automated threat hunting with comprehensive detection rules, automated risk assessments, and incident response.

SecOps teams continue to move ahead with automated threat hunting and detection engineering capabilities to help reduce human error, alert fatigue, and more accurate intrusion analysis.

Why is Threat Hunting Important for Cybersecurity Professionals?

Without threat hunting, SecOps teams and the organization will remain in a very reactive state regarding cybersecurity response. The volume of AI-powered hacking attacks creates a no-win situation for an organization remaining in the reaction mode instead of a proactive mindset.

Threat hunting becomes the critical piece in the journey to transform the organization from a reactionary to a more proactive cybersecurity culture. By looking proactively for IoCs, tactics, techniques, and procedures (TTP) documented within the MITRE ATT&CK Framework, the organization can adjust their current defensive capabilities and processes ahead of their adversaries.

Key Components of Threat Hunting Tools and Resource Allocation

When establishing a cyber threat hunting checklist, SecOps needs to break the plan into four phases to ensure the execution is effective, repeatable, and fluid.

Preparation

Within the preparation phase, SecOps teams, along with the senior leadership team, need to define the objectives for the threat hunting engagement. After the objectives become clearly defined, SecOps needs to list their sources for gathering intelligence. Most SecOps teams have access to global threat intelligence feeds and open-source material they can use to help with the threat hunting engagement. Another critical piece of the preparation phase includes the selection and enablement of various tools to assist with the engagement.

Threat hunting tools include endpoint security agents, next-generation firewalls, network detection and response (NDR) solutions, and intrusion prevention agents.

Data Collection

Threat hunting only works if the SecOps teams collect valuable telemetry from trusted sources. SecOps teams that deploy endpoint security agents will gain the benefit of collecting valuable and relevant telemetry information. Additionally, SecOps teams also gain immeasurable value in collecting information from networking devices, firewalls, border routers, and cloud security solutions, including Cloud Access Security Broker (CASB) solutions. Another incredible source of valuable telemetry exists with zero-trust authentication security logs.

Once the SecOps teams have determined which telemetry resources they plan to collect from, they need to determine how much data needs to be captured and where the information needs to be stored. Security Information and Event Management (SIEM) tools remain an ideal repository for SecOps to store the data for analysis.

Collecting too little or too much data will affect the threat hunter’s ability to create valuable threat intelligence information with actionable insight. Too little data may cause a false detection of a threat.

Detection Method

Once the data collection phase becomes defined, the next stage focuses on developing the detection process. SecOps teams need to define how best to use the collected data within a process flow to help deliver valuable insight into threats.

The first step in developing the detection method is creating an initial baseline. Next step, access IoC sources to help match possible ones discovered during the threat hunting exercise. These IoC sources include feedback from IBM, BlackBerry Global Intelligence, VirusTotal, and the Cybersecurity Infrastructure and Security Agency (CISA).

Advanced Analysis Powered by AI and ML

Prior to artificial intelligence (AI) and machine learning (ML), SecOps teams used a mix of behavior-based analytics and signature-based threat tools to process the collected data against the various threat intelligence feeds. With access to AI and ML tools, threat hunters now have access to a faster and more accurate analysis of threats learned from previous telemetry.

Defining Key Areas of Concern Based on Risk and Overall Impact

Once the tools, data collection, and detection strategy have been defined, the next phase in the threat hunting checklist is defining where SecOps needs to begin to hunt within the enterprise environment.

Threat hunting ideally is needed across every aspect of the enterprise environment. However, it is not realistic to capture and analyze every element of network traffic, account login information, or TCP connections across the border router, switching core, cloud instances, and every endpoint. SecOps needs to focus on what attack vectors will cause the greatest damage against their organization and what assets are most likely going to be the top target.

For example, hackers leveraging email phishing for ransomware attacks will first look towards the weakness in messaging security. By placing malicious links loaded with malware instead of well-crafted emails, there will be a large number of users that will click on the link and mistakenly download and kick off a ransomware attack.

As a result of this email phishing attack, SecOps needs to hunt for ransomware tactics, including lateral movement between hosts within the same network segment or attempts by the malware to communicate externally to command-in-control servers.

Another common attack vector used by hackers is the exploitation of weak and default passwords within the Active Directory (AD) administrative groups. By gaining access to AD administrative groups, hackers can increase their privileges while removing others from the same group. This hijacking of administrative permissions is a very common and successful attack vector.

Ultimately, these attack vectors either become a single-thread or full kill chain attack, resulting in a data exfiltration breach. Data exfiltration breaches result in the organization facing countless lawsuits, compliance violations, and loss of trust from their customers, employees, and partners.

Documenting and Reporting Findings

Effective threat hunting is about discovering vulnerabilities, existing persistence attacks, and what future exploitations could resemble. After a completed threat hunting engagement, SecOps teams need to document their findings along with remediation recommendations to help the organization reduce their risk of future attacks. This documentation will prove valuable if the organization plans to apply for cyber insurance or SOC 2 compliance or must explain a security breach to law enforcement.

Here are critical components all threat hunting reports should include.

  • Summary: The SecOps team needs to craft a summary of the engagement, including method, source of data, tools used, and what elements within the enterprise environment were the core focus.
  • Remediation Recommendations: SecOps needs to provide a priority of remediation based on the Common Vulnerability Scoring System (CVSS) score to help the organization focus on the highest- to low-risk areas of concern.
  • Noted Areas of Concern: SecOps needs to craft a narrative disclosing areas of concern, including issues discovered that were a complete surprise or could become a much bigger issue in the future.
  • Conclusion: SecOps needs to provide artifacts and a conclusion on how this threat hunting helped reduce the organization’s risk.

Continuous Improvement in Threat Hunting Strategies

Organizations moving ahead with threat hunting exercises need to consider a continuous monitoring strategy between this engagement. Managed detection and response (MDR) services from ForeNova help organizations monitor their most critical assets between threat hunting engagements to look for any possible new threats. MDR services also help organizations recognize potential areas missed during the threat hunting exercise.

Noodlophile InfoStealer Unmasked: How AI Ads on Facebook Delivered a Python-Based Data Theft Chain

Attackers used Facebook to promote AI generated ads to lure users to a malicious website. The ad claimed to convert still images into vivid videos. After the fake progress bar reached 100%, users got a downloadable ZIP archive, which containd the following:

Among the contents was an executable file deceptively named “Video Luma MachineAI.mp4.exe”, multiple Unicode no-break space characters (\xe2\xa0\x80) were used between .mp4 and .exe to impersonate a video file. The folder 5.0.0.1886 had both system and hidden attributes, making it invisible by default in file explorers.

When the user double-clicks the .exe file, it runs “Capcut.exe” located in the 5.0.0.1886 directory and then exits the current process.

“CapCut.exe” is a .NET executable. Upon running, it repeatedly accesses “https[:]//google.com”, then briefly pauses. It then proceeds to rename files in the 5.0.0.1886\software directory, meta becomes “image.exe” and Document.docx becomes install.bat. The renamed image.exe is actually WinRAR, and install.bat is then executed.

The batch script decodes Document.pdf into ppIuqewlq.rar, which is silently extracted using “image.exe” into %LOCALAPPDATA%\SoftwareHost, with the extraction password being TONGDUCKIEMDEVELOPER2025. The extracted content includes a Python runtime environment and its dependencies. The file srchost.exe is essentially “python.exe”:

Using srchost.exe, the malware downloads and executes remote code. The downloaded script uses exec() to execute a marshaled (serialized) Python object. The marshaled object is then decompiled for analysis:

The disassembled opcodes amount to over 60,000 lines, but most are garbage instructions designed to hinder analysis. The meaningful opcodes are in the last 500 lines. To facilitate analysis, AI tools are used to reconstruct the original Python code from these opcodes.

Although the AI-reconstructed code might differ from the original, it provides a helpful base for manual verification. Eventually, another marshaled object is uncovered, and the same decompilation method is applied to retrieve its source code.

The final code carries out data theft, targeting: Browser cookies, Browse history and saved credentials, Stored credit card information, Facebook login credentials and account data:

All stolen data is archived and sent to a Telegram bot before being deleted from the victim machine.

BlackLock Ransomware Deep Dive: A Cross-Platform, Double Extortion Threat

Malicious File Summary

Malware FamilyBlackLock
Release DateFebruary 25, 2025
Threat TypeRansomware
Brief DescriptionBlackLock ransomware (also known as El Dorado or Eldorado) emerged in March 2024 and operates under a Ransomware-as-a-Service (RaaS) model. It employs a double extortion strategy—encrypting data and stealing sensitive information—and targets Windows, VMware ESXi, and Linux environments. Victims span various industries and regions.

Sample Analysis

Summary

The sample requires administrator privilege to execute and must be run via the command line; it does not launch via double-click.

Upon execution, the following log is printed:

Ransom note content:HOW_RETURN_YOUR_DATA.TXT

Example of encrypted files:

Analysis

Windows Version

Supported optional parameters for execution:

ParameterDescription
-pathSpecifies the file path to be encrypted
-skip-localSpecifies files to be excluded from encryption
-n <subnet>Specifies shared resources in CIDR format, e.g., 192.168.5.0/24
-d <domain>Specifies the domain
-u <username>Specifies SMB account
-p <password>Specifies SMB password
-skip-netSkips encrypting shared directories

When provided with appropriate user credentials, it can encrypt files on shared networks using the SMB protocol.

Logs are transmitted via WebSockets to 173.44.141[.]152, with the Origin header set to “http://logger”

To eliminate traces, the Eldorado ransomware runs a PowerShell command to overwrite the encryptor executables with random bytes and then deletes the file. If the “-keep” parameter is specified, this action is skipped:

Linux Version

The Linux variant is simpler, supporting only the -path parameter.

It recursively encrypts files within the specified directory using the same encryption algorithm as the Windows version.

Indicators of Compromise (IOC)

SHA256 windows1375e5d7f672bfd43ff7c3e4a145a96b75b66d8040a5c5f98838f6eb0ab9f27b
7f21d5c966f4fd1a042dad5051dfd9d4e7dfed58ca7b78596012f3f122ae66dd
cb0b9e509a0f16eb864277cd76c4dcaa5016a356dd62c04dff8f8d96736174a7
0622aed252556af50b834ae16392555e51d67b3a4c67a6836b98534a0d14d07d
8badf1274da7c2bd1416e2ff8c384348fc42e7d1600bf826c9ad695fb5192c74
SHA256 Linuxb2266ee3c678091874efc3877e1800a500d47582e9d35225c44ad379f12c70de
dc4092a476c29b855a9e5d7211f7272f04f7b4fca22c8ce4c5e4a01f22258c33
Malicious IP173.44.141.152
Ransom Note FilenameHOW_RETURN_YOUR_DATA.TXT
Encrypted File Extensions.63npoxa6、.00000001
Dark Web URLshttp://dataleakypypu7uwblm5kttv726l3iripago6p336xjnbstkjwrlnlid.onion
Dark Web URLshttp://panela3eefdzfzxzxcshfnbustdprtlhlbe3x2fqomdz7t33iqtzvjyd.onion/Url=ddb34da5-dce4-4b46-8f7d-4674ab38be9d
Commandlinevssadmin delete shadows /all /quiet
Directories Excluded from EncryptionWindows, programdata, program files, program files (x86), $recycle.bin, all users, winnt, appdata, application data, local settings, boot
Files Excluded from Encryptionntldr, ntdetect.com, autoexec.bat, ntuser.dat, ntuser.dat.log, iconcache.db, bootsect.bak, bootfont.bin, bootmgr, thumbs.db
File Extensions Excluded from Encryption.00000001, .exe, .dll, .sys, .msi, .ini, .inf, .lnk,.63npoxa6

Cybersecurity Alert Fatigue in Healthcare IT Security Operations

Imagine having a job where you do nothing more than respond to events with no clear resolution. While you are trying to solve one problem, 10 more show up, then 20, and then 30. Cybersecurity teams live with this reality of increasing alert volume, alert fatigue, false alarms, and hundreds of thousands of actual threats entering the hospital network.

A decade after a key AACN Advanced Critical Care article, alarm fatigue remains a concern for researchers, clinicians, and organizations.

“It leads to missed alarms medical errors causing patient deaths, increased workloads, burnout, a drop in job satisfaction, and hinders patient recovery.”

Are you seeing increased cyberattacks against your medical records and other data sources?

Learn about a fresh approach to cybersecurity and a better way to deal with the overwhelming volume of excessive alerts with the NovaMDR offering from the team at  ForeNova!

Click here to schedule a demo with the team at ForeNova today.

How Has Alert Fatigue Affected the Healthcare Industry?

With the increase in cyberattacks and their effects on SecOps resources, hackers know it is only a matter of time before their attack vectors find their targets within a healthcare network. Hackers, like hospitals and medical providers, continue to invest in AI and ML to increase their attack velocity and complexity.

Healthcare providers holding back on investing in AI-defensive tools, additional training, and recruitment of SecOps talent, including skilled security analysts, will quickly expose their applications, medical records, and all IP-enabled medical devices to internal and external hackers.

In healthcare, for example, once a medical provider switched from paper to electronic medical records (EMR), the number of cyberattacks and malicious activities tripled quickly.

This increase in attack vectors, combined with the lack of human capital resources and updated tools powered by artificial intelligence (AI) and machine learning (ML), created an unsustainable work environment for SecOps engineers and other organization members. Alert fatigue continues to impact healthcare organizations.

This constant game of catch-up became the interesting reality security operations engineers face daily. They try to resolve genuine threats while dealing with increasing security alerts that turn out to be false positives. Cyberattacks’ velocity and sheer volume grow daily across every market sector, including healthcare, finance, and government. High-priority alerts mix with low-level alerts as more legacy security systems cannot understand the new alerts, including next-generation malware activity.

Hackers leverage AI to adjust their various attack vectors quickly, alter their destinations, and increase the attack volume within seconds.

AI-defensive tools are essential to stop AI-offensive tools used by hackers.

Impact of Alert Fatigue on Patient Data Protection

A 2023 study found that 62% of healthcare IT staff felt unprepared for rising cybersecurity threats.

Failing to keep pace with AI-enabled cyberattacks against healthcare systems results in data breaches, account takeovers, and even the shutdown of critical emergency room equipment. The increased volume of security incidents is only one part of the problem. Notification fatigue, adjusting alert thresholds, and overall mental health become even more significant challenges for healthcare providers.

Why Are Healthcare Providers a Prime Target for Hackers?

EHRs are valuable to cybercriminals, containing medical records, diagnoses, and billing information. The average cost of a data breach is $10.93 million, making healthcare the most affected industry.

Reports show the value of a health record can be worth as much as $1,000, whereas on the dark web, a credit card number is worth $5 and Social Security numbers are worth $1.”

Ransomware Continues to be a Top Attack Vector

Ransomware is a significant threat to healthcare, making up 54% of cyber incidents per ENISA.”

Alarmingly, nearly half led to data breaches, like the Vice Society attack on the Parisian maternity hospital Pierre Rouquès—Les Bluets. After the hospital refused to pay the ransom, the Vice Society released 150 GB of patient data on the dark web.

What Are the Top Healthcare Cyberattacks in Germany in 2024?

Like others in the EU, German healthcare providers faced a considerable amount of cyberattacks in 2024. These attacks focus on several attack vectors, including phishing, resulting in ransomware malware, attacks on Internet-of-things (IoT) devices, and data exfiltration from EMR systems.

As the medical industry continues investing in digital transformation, including cloud-based applications, fatigue will probably impact its SecOps resources.

Mittelfranken District Hospital

The Mittelfranken District Hospital is one of many victims of hacker attacks. In recent months, there has been a particular increase in attacks on hospitals.

Unknown individuals accessed the IT systems of Middle Franconia District Hospitals and encrypted data. The timeline for restoring systems after the attack is uncertain. As a precaution, all systems have been disconnected. Hospital management promptly informed relevant authorities, including the police and data protection officials.

Wertach clinics in Bobingen and Schwabmünchen

“According to the report, the server systems’ failure severely restricted clinic operations, forcing them to switch to an analog emergency structure. The clinic canceled planned operations, and further cancellations are possible.”

A hacker attacks targeted Reinhardshausen’s Spa Park Clinic.

Hackers attacked Klinik Kurpark’s central data system. The clinic is resolving the issue and maintaining transparent communication with affected parties.

Law enforcement reported that a urological follow-up treatment clinic was “attacked by cybercriminals on August 27th,” disrupting central IT systems. Technicians quickly isolated, checked, and secured the systems and immediately took measures to contain the incident.

Enabling AI and ML for Healthcare SecOps Automation

Alert fatigue continued to impact traditional SecOps within healthcare, resulting in cybersecurity branches. As more healthcare invests in AI SecOps, the more significant the positive impact they have, reducing alert fatigue while blocking more active attacks.

AI SecOps includes several pillars, including:

AI-Powered Threat Detection

AI-driven threat detection relies on machine learning algorithms to analyze network traffic, user behavior, and threat intelligence feeds. This capability allows the AI to learn and differentiate between normal and abnormal activities, improving the accuracy of threat alerts and detecting anomalies sooner to reduce significant breach risks.

Automated Incident Response

Automated incident response allows AI systems to execute predefined playbooks to contain threats. For instance, AI can quarantine infected devices or block malicious IP addresses immediately upon detection. This swift action helps curb the spread of malware and minimize system damage.

Automation of Routine Tasks

AI streamlines routine security tasks by automating patch management, malware scanning, and network monitoring. This process allows human experts to focus on complex issues while ensuring consistent application of basic security measures, lowering the risk of human error.

Increase Security Awareness Training for the User Community

Healthcare workers use email extensively, along with patient portal applications. Extending access to cybersecurity education will help them become more aware of these attacks and understand their impact on the healthcare system by providing security awareness and attack simulation exercises.

Fact: Most importantly, preventing more attacks at the user level reduces the number of alerts SecOps teams must handle.

The Future of Cybersecurity for Healthcare in 2025

2025 for healthcare will be far more than just AI-powered new cybersecurity tools. New US and EU compliance mandates will profoundly impact the healthcare industry.

U.S. lawmakers have introduced two bills, the Healthcare Cybersecurity Act of 2024 and HISAA, to enhance protections for sensitive health data. However, they remain stalled in the legislative process and are not yet law.

Focusing on the Healthcare Mission

Healthcare providers aim to enhance patient outcomes. However, cybersecurity’s increasing complexity diverts focus and resources. Outsourcing cybersecurity functions allows organizations to prioritize care delivery while keeping systems secure.

In 2025, healthcare cybersecurity protection and success depend on leveraging the right partnerships, technologies, and strategies to protect what is essential.

What is the role of Managed Detection and Response (MDR)?

As AI SecOps tools advance in functionality and effectiveness for the healthcare industries, these tools do not configure themselves, nor are they a plug-and-play-and-forget solution.

Healthcare struggling with access to financial capital and SecOps engineering talent look to MDR providers like ForeNova to help.

Why ForeNova?

MDR providers like ForeNova have experience with AI tools, access to global engineering talent, and a proven proactive approach that aligns with healthcare operations requirements and compliance mandates.

The cost is significant for healthcare providers looking to leverage NovaMDR by ForeNova. The ForeNova team understands the financial challenges more healthcare providers face in Germany and continues to develop cost-saving licensing and service models embedded within the NovaMDR offering.

NovaMDR by ForeNova helps organizations phase out legacy security devices, improve their cybersecurity posture, reduce the need to hire additional talent, and enhance overall security response.

Stopping cyberattacks begins with partnering with an MDR provider like ForeNova, which understands the landscape facing German healthcare SecOps engineers experiencing alert fatigue.

Click here to schedule your free demo of NovaMDR today!

A Deep Dive into Advanced Persistent Threats (APT)

You may well have heard of advanced persistent threats (APT) from recent high-profile APT attacks, such as the SolarWinds supply chain attack. But what are advanced persistent threats? How are they different from other cyber-attacks?

Continue reading “A Deep Dive into Advanced Persistent Threats (APT)”

What is a Supply Chain Attack? – ForeNova Technologies

In December 2020, U.S. software developer SolarWinds was exposed as the victim of a major cyber-attack. The threat actor behind the attack installed a backdoor into the software updates of its Orion Platform. The backdoor gave the attacker direct access to the computer networks of 18,000 Orion customers. These include the highest echelons of the U.S. government and some of the world’s largest enterprises.

Continue reading “What is a Supply Chain Attack? – ForeNova Technologies”

Immer up to date!

Abonnieren Sie unseren Newsletter und erhalten Sie wertvolle Branchen-Insights, Produkt-Updates und aktuelle Analysen von ForeNova direkt in Ihr Postfach.

Wir verwenden Brevo als unsere Marketing-Plattform. Indem Sie das Formular absenden, erklären Sie sich einverstanden, dass die von Ihnen angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden, gemäß den Datenschutzrichtlinien von Brevo.