The story so far
The Hunt or be Hunted series has been telling one kind of story: a HuntIQ threat hunter walks into a customer environment, runs a hunt, and finds something meaningful. ShieldBreak. FalconFlank. RunMRU. On every one of those posts, we kept getting the same question: how do I run this in my own environment?
That is what HuntIQ Tradecraft is for.
What HuntIQ Tradecraft is
HuntIQ Tradecraft is a growing library of hunt playbooks published on TRC. Each entry is written by the same threat hunters who run the hunt in customer environments, and each one gives you what you need to execute it against your own estate:
- The hypothesis — what attacker behavior the hunt is looking for, and why.
- The sensor question — the exact Tanium query to run.
- The filtering method — how to reduce noise without losing the signal.
- ATT&CK mapping — so you can compare against what your existing content already covers.
- False-positive patterns — the legitimate activity that will look suspicious, and how to tell the difference.
- Preconditions and limits — what has to be true for the hunt to work, and what it will and will not tell you.
Not marketing pieces. Playbooks. Written for defenders, in the language defenders use.
A few examples of what is inside
Live today:
- When Volume Is the Finding — a hunt where the alert volume itself is the tell. What the pattern looks like, why rule-based detection misses it, how we surface it in Tanium.
- Hunting service execution from user-writable directories with Tanium — a persistence and privilege-escalation primitive most SOCs never hunt. The concrete Tanium sensors and queries that expose it.
Landing over the coming weeks:
- Hunting TerminalFix when there is nothing to patch — what to hunt for when the fix is behavioral rather than a KB number.
- Hunting COM hijacking and CLSID abuse with Tanium — a low-noise, high-value persistence primitive that survives most rule-based detection.
- Alternate Data Stream (ADS) hunting — the NTFS surface most tooling never inspects.
- DLL sideloading — the defense-evasion primitive that keeps working because everyone loads DLLs.
- WMI Event Subscription persistence — the sophisticated-actor foothold that lives outside normal autoruns.
- RunMRU for credential exposure — hunting the place users actually type, and what that catches beyond the hypothesis you built it for.
The catalog will keep growing. If a hunt earned its keep in a customer environment, it will end up here.
Where the HuntIQ service fits
HuntIQ Tradecraft is what any Tanium customer can pick up and run. HuntIQ, the service, is the people who wrote it.
When you engage HuntIQ, expert threat hunters work hands-on inside your Tanium deployment with you. They run the playbooks in HuntIQ Tradecraft. They tune your detection content. They build new hunts against the techniques attackers are using elsewhere in the landscape. And they do it with Atlas — Tanium’s autonomous operating system — dispatching every relevant Tanium capability in parallel across your fleet the moment a hypothesis takes shape. What used to take hours of triage, scoping, correlation, and containment now finishes in minutes, with a structured verdict staged for your one-click approval.
The tradecraft is public for Tanium customers. The judgment is the service. If you want both, that is what HuntIQ is.
How to use HuntIQ Tradecraft in your environment
- Go to help.tanium.com (opens in a new tab) and navigate to HuntIQ Tradecraft.
- Pick a playbook that maps to a coverage gap you know you have. Read the hypothesis. Run the sensor question against your own estate. Work through the filtering method.
- Read the ATT&CK mapping against your existing content. If nothing you run already covers that technique the same way, you have a new detection to add.
- Come back as new tradecraft posts land on a regular cadence, drawn from what our hunters are finding right now.
Start hunting
- Read the HuntIQ Tradecraft playbooks on TRC (opens in a new tab) (Tanium customer TRC access required).
- Learn about the HuntIQ service.
- Catch up on the Hunt or be Hunted series on the Tanium blog for the customer-anonymous stories behind the tradecraft.