Skip to content

Hunting Beyond Indicators - Part 2

Published: at 03:00 PM

I published a follow-up to my THOR Collective guest post on hunting beyond Indicators of Compromise. Part 2 puts the methodology into practice with two examples from ICS/OT-focused threat hunting: KurtLar_SCADA and a strange .NET Modbus binary.

The post walks through the hypotheses that led to those discoveries, how I triaged noisy hunting results, and why evidence-based assessment matters when suspicious behavior is not enough to confidently call something ICS malware.

Hunting Beyond Indicators - Part 2 by Sam Hanson

Read on Substack

Give it a read if behavior-based threat hunting, ICS protocols, or weird malware-adjacent binaries are your thing.