Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Hunting for Discovery Level 2

Solution Category Threat Intelligence
Type Webinar
Organization Intel 471
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Advanced threat hunting workshop focusing on the Discovery phase of cyber intrusions
  • Hands-on analysis of system enumeration, account queries, and adversary tooling
  • Designed for SOC analysts, threat hunters, incident responders, and security engineers
  • Integrates threat intelligence to connect technical findings with adversary intent
  • Virtual, interactive format led by Intel 471’s Lee Archinal

Introduction

The Threat Hunting Workshop 19: Hunting for Discovery – Level 2 is a virtual training session designed for cybersecurity professionals seeking to strengthen their capabilities in detecting adversary reconnaissance within enterprise networks. Hosted by Intel 471 and led by Lee Archinal, Principal Threat Hunt Account Manager, the workshop addresses one of the most critical yet often overlooked phases of cyber intrusions: the Discovery phase, where attackers systematically map environments to identify high-value targets before escalating their operations.

As threat actors become increasingly sophisticated in their pre-attack reconnaissance, security teams face mounting pressure to detect these subtle behaviours before they escalate into data exfiltration or ransomware deployment. This workshop responds to that challenge by equipping participants with practical frameworks and analytical techniques grounded in real-world threat intelligence.

Understanding the Discovery Phase

The Discovery phase represents a pivotal stage in the attack lifecycle where adversaries transition from initial access to active reconnaissance within a compromised environment. During this phase, attackers enumerate systems, query account permissions, and map network architecture to understand what resources exist and how they might be exploited. These activities often precede lateral movement and privilege escalation, making early detection essential for limiting the scope of an intrusion.

Unlike the noisier stages of an attack, Discovery behaviours can blend with legitimate administrative activity, presenting significant detection challenges for security operations teams. Distinguishing between a system administrator running routine queries and an adversary conducting reconnaissance requires both technical expertise and contextual understanding of normal baseline behaviour within an environment.

Workshop Content and Methodology

Participants work through scenario-based exercises that simulate real adversary behaviour, analysing system and network enumeration activity alongside account and permission queries. The workshop examines common adversary tooling used during Discovery operations, helping attendees recognise the artefacts and patterns these tools leave behind in logs and telemetry data.

A distinguishing feature of this training is its integration of threat intelligence throughout the analytical process. Rather than treating detection as a purely technical exercise, the workshop guides participants in connecting their findings to broader adversary intent. This approach helps threat hunters understand not just what happened, but why an attacker might have taken specific actions and what their likely next steps could be.

The session provides a repeatable framework for hunting Discovery behaviours that participants can apply within their own environments. This structured methodology is designed to work across common security platforms, including SIEM, EDR, and NDR solutions, regardless of the specific vendor implementations in use.

Who Should Attend

The workshop is structured for cybersecurity professionals with intermediate experience who are looking to deepen their threat hunting capabilities. Threat hunters, SOC analysts, incident responders, and security engineers working in enterprise environments will find the content most directly applicable to their daily responsibilities. The Level 2 designation indicates that participants should have foundational knowledge of threat hunting concepts before attending.

Security team members who regularly investigate alerts or conduct proactive hunts will benefit from the practical, hands-on nature of the exercises. The workshop also serves professionals seeking to bridge the gap between threat intelligence consumption and operational security practice, translating strategic threat knowledge into actionable detection techniques.

Practical Application and Outcomes

Beyond the live instruction, participants receive supporting reference materials to reinforce the concepts covered during the session. Those who complete a final challenge following the workshop can earn a digital badge recognising their achievement. The interactive format ensures that attendees engage directly with realistic data rather than passively consuming lecture content, reinforcing skills through practical application.

For organisations investing in their security teams’ professional development, workshops of this nature address a persistent skills gap in the cybersecurity workforce. The ability to hunt effectively for pre-attack behaviours represents a proactive security posture that complements traditional alert-driven detection, potentially reducing dwell time and limiting the impact of successful intrusions.