Guide
How to threat hunt with Open NDR + MITRE ATT&CK
This Threat Hunting Guide leverages MITRE ATT&CK—a global knowledge base of real-world adversary tactics—to teach proactive discovery of attacks using Corelight's Open NDR network data. Organized by ATT&CK framework, it helps develop hunting theories and prioritization for private sector, government, and cybersecurity teams. Corelight enables effective hunts by providing rich, structured Zeek logs and telemetry mapped to ATT&CK techniques—uncovering stealthy threats pre-impact, bridging observations to actionable defenses, and fostering community-driven safer strategies.
