Black GhostBlack Ghost
Blue Team · Defensive

Threat Hunting.
Finding what the alerts miss.

Proactive hunting for threats that already slipped past automated defenses. We start from hypotheses based on real adversary TTPs and hunt for indicators of compromise before they become an incident.

Operational capability available today. Part of building a national cyber defense.

ProactiveHypothesis-drivenMITRE ATT&CKThreat intel

[ 01 / WHAT WE HUNT ]

What the alerts do not see.

Hidden persistence

Persistence mechanisms that survive reboots and go unnoticed by antivirus.

Lateral movement

Use of valid credentials and legitimate tools (living off the land) to move through the environment.

Silent exfiltration

Data egress channels disguised as normal traffic.

Compromised accounts

Anomalous behavior in legitimate accounts that triggers no automated rule.

[ 02 / HOW WE HUNT ]

From hypothesis to lasting detection.

  1. 01

    Hypothesis

    We start from known TTPs and your context to formulate concrete compromise hypotheses.

  2. 02

    Collection & analysis

    Investigating endpoint, network, identity and log telemetry in search of evidence.

  3. 03

    Validation

    Confirming or ruling out each hypothesis, with immediate escalation if something is found.

  4. 04

    Lasting detection

    Every finding becomes a new detection rule: today’s hunt is tomorrow’s alert.

[ 03 / WHAT YOU GET ]

More than a report.

A report of the hypotheses tested and what was found or ruled out.

Indicators of compromise and artifacts for your detection base.

New detection rules derived from the hunt.

Visibility recommendations where telemetry was missing.

Are you sure nobody is already inside?

Talk to our specialists. We formulate hypotheses for your environment and hunt what the alerts miss.