<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://threathunt.blog/how-to-start-with-host-based-threat-hunting/</loc>
<lastmod>2022-04-10T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/hunt-for-a-hidden-scheduled-task/</loc>
<lastmod>2022-04-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/dll-image-loads-from-suspicious-locations-by-regsvr32-exe-rundll32-exe/</loc>
<lastmod>2022-04-20T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/running-multiple-instances-of-discovery-commands-in-short-period-of-time/</loc>
<lastmod>2022-04-30T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/bzz-bzz-bumblebee-loader/</loc>
<lastmod>2022-05-08T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/amsi-bypass-mde-detection/</loc>
<lastmod>2022-05-27T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/detecting-follina-with-mde/</loc>
<lastmod>2022-06-05T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/detecting-a-payload-delivered-with-iso-files-using-mde/</loc>
<lastmod>2022-07-17T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/running-live-malware-for-threat-hunting-purposes/</loc>
<lastmod>2022-08-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/from-shodan-to-mde-queries/</loc>
<lastmod>2022-09-04T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/recent-phishing-emails-emotet-recent-sample-analysis/</loc>
<lastmod>2022-11-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/my-version-of-a-home-lab/</loc>
<lastmod>2022-11-19T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/qakbot/</loc>
<lastmod>2022-11-22T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/mde-mdi-mdo365-advanced-hunt-queries-to-elk/</loc>
<lastmod>2022-11-28T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/html-smuggling-how-does-it-look-like/</loc>
<lastmod>2022-12-18T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/asyncrat/</loc>
<lastmod>2023-01-08T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/hunting-for-msbuild-based-execution/</loc>
<lastmod>2023-01-21T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/malware-statistics-to-elk/</loc>
<lastmod>2023-02-16T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/analysis-of-the-current-malware-icedid/</loc>
<lastmod>2023-03-19T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/Turla/</loc>
<lastmod>2023-05-19T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/threat-intelligence-platform-opencti/</loc>
<lastmod>2023-07-06T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/opencti-rss-feed-support/</loc>
<lastmod>2023-09-16T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/rare-process-launch-as-a-service/</loc>
<lastmod>2024-02-05T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/hunt-seo-poisoning/</loc>
<lastmod>2024-02-23T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/lsass-credential-dumping/</loc>
<lastmod>2024-03-11T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/impacket-psexec/</loc>
<lastmod>2024-04-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/impacket-part-2/</loc>
<lastmod>2024-04-27T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/impacket-part-3/</loc>
<lastmod>2024-06-01T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/the-dfir-thing/</loc>
<lastmod>2024-07-27T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/the-dfir-thing-reg-parsing-1/</loc>
<lastmod>2024-08-29T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/hunting-for-malicious-scheduled-tasks/</loc>
<lastmod>2024-10-06T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/wsl/</loc>
<lastmod>2024-11-10T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/registry-hunts/</loc>
<lastmod>2025-02-08T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/new-mde-fields/</loc>
<lastmod>2025-02-28T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/scattered-spider/</loc>
<lastmod>2025-06-21T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/tidashboar/</loc>
<lastmod>2025-11-30T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/th-novelty/</loc>
<lastmod>2026-02-24T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/autonomous-soc/</loc>
<lastmod>2026-03-14T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/autonomous-soc-part2/</loc>
<lastmod>2026-03-24T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://threathunt.blog/404/</loc>
</url>
<url>
<loc>https://threathunt.blog/about.html</loc>
</url>
<url>
<loc>https://threathunt.blog/author-jouni.html</loc>
</url>
<url>
<loc>https://threathunt.blog/authors-list.html</loc>
</url>
<url>
<loc>https://threathunt.blog/buy-me-a-coffee.html</loc>
</url>
<url>
<loc>https://threathunt.blog/categories.html</loc>
</url>
<url>
<loc>https://threathunt.blog/contact.html</loc>
</url>
<url>
<loc>https://threathunt.blog/</loc>
</url>
<url>
<loc>https://threathunt.blog/privacy-policy.html</loc>
</url>
<url>
<loc>https://threathunt.blog/tags.html</loc>
</url>
<url>
<loc>https://threathunt.blog/page2/</loc>
</url>
<url>
<loc>https://threathunt.blog/page3/</loc>
</url>
<url>
<loc>https://threathunt.blog/page4/</loc>
</url>
</urlset>
