All playbooks
Threat hunting · Threat hunters and SOC analysts
Pivot from one suspicious event
Expand from a lead across entity, time and behavior without losing scope.
Keep the original event visible while you widen to related entities and adjacent behaviors.
What this does not establish
- A shared IP can represent unrelated users behind a proxy or VPN.
- A matching filename does not prove the same binary or behavior.
- A wider query can hide the original event's exact context.
0 of 8 ticked
Selected step
FrameStep 1 of 8
Anchor the hunt to one preserved lead.
Save the original event and timeline
- Keep source, event ID, asset, user and observed time.
- Record why this event deserves a pivot.