Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

When to Conduct Structured and Unstructured Threat Hunts

SANS via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to distinguish between structured hypothesis-driven threat hunts and unstructured data-led threat hunts in this 34-minute conference talk from the SANS DFIR Summit 2025. Explore when to apply each methodology based on different triggers such as intelligence reports or advanced persistent threat (APT) activity that can initiate structured hunts. Discover how unstructured hunts develop through data discovery processes and understand the distinct objectives each approach serves in threat hunting operations. Gain practical insights from industry experts Lee Archinal, Senior Threat Hunt Analyst at Intel 471, and Arun Warikoo, Head of Cyber Threat Intelligence at CIB Americas BNP Paribas, as they guide you through making strategic decisions about which hunting approach to deploy in various scenarios to effectively identify and mitigate threats in your environment.

Syllabus

When to Conduct Structured and Unstructured Threat Hunts

Taught by

SANS Digital Forensics and Incident Response

Reviews

Start your review of When to Conduct Structured and Unstructured Threat Hunts

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.