Use when evaluating threat detection opportunities (TDOs), generating synthetic UDM events, evaluating Chronicle rule coverage, and drafting YARA-L 2.0 rules.
Use when hunting for advanced persistent threat (APT) actor activity, tools, and infrastructure.
Use when hunting for lateral movement via PsExec, WMI, remote scheduled tasks, or WinRM.
Use when initiating threat hunting operations driven by GTI threat campaign intelligence.
Use when conducting initial reputation and threat intelligence lookups on suspicious observables.
Use when performing exhaustive forensic and intelligence analysis on complex indicators of compromise.
Use when enriching and verifying case artifacts with external threat intelligence platforms.
Use when executing network, host, or credential containment actions for validated malicious IOCs.