Hunt Methodology

All reports follow a structured format: Hypothesis → Scope → Data Sources → Query/Logic → Findings → Detection Output. Tactics and techniques are mapped to MITRE ATT&CK Enterprise. Where applicable, Sigma rules or KQL detection logic is included.