nesrine cherrabi

THREAT HUNTER

home / writing

Field notes

Notes from the hunt, written for lean teams.

Practical writing on threat hunting, incident response, and detection engineering, no vendor spin, no fear-mongering. Just what actually works when you’re defending with a small team.

Unmanaged PowerShell Execution: Hunting Beyond powershell.exe

Attackers increasingly run PowerShell without ever touching powershell.exe, loading the engine straight into other processes to slip past the obvious detections. This piece walks through hunting that unmanaged PowerShell execution in Elastic, with Sigma logic your SOC can put to work.

Read More »

Hunting Scheduled Tasks

Scheduled tasks are a normal part of system operations, they help with updates, backups, and maintenance jobs.But attackers love them

Read More »

Threat Hunting with Osquery Manager

When is osquery the right tool for a hunt? This walkthrough takes a command-and-control scenario end to end with Osquery Manager, then turns the findings into reusable detections and YARA-based scanning.

Read More »
Scroll to Top