InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Hunt Hub: Opening the Black Box of EDR Detection

Presented by

Nikita Nazarov, Head of Threat Exploration; Gleb Ivanov, Malware Analyst Team Lead

About this talk

You can read about detection logic. Or you can see how it actually works. In this webinar, Kaspersky experts will open Hunt Hub live inside our Threat Intelligence portal and show how detection logic is built, structured, and used in practice — in direct connection with threat actors, campaigns, and techniques observed in the wild. For a long time, detection rules often looked like a “black box” to customers. Today, this logic is transparent and accessible through the Threat Intelligence portal, allowing analysts to understand why a detection exists, which actor behavior it covers, and how it relates to known threat activity. This is a hands-on session focused on practice. Our speakers will show: • How detection rules are organized and maintained inside Hunt Hub and linked to TI data • How rules map not only to MITRE ATT&CK, but also to specific threat actors and campaigns • How analysts can read, validate, and interpret detections in a SIGMA-like format • How to use this knowledge to speed up investigations and reduce false assumptions • How to use Hunt Hub proactively to anticipate relevant threats, and reactively during investigations • What experienced SOC teams should pay attention to when working with detection logic Beyond the walkthrough, our experts will share practical tips and best practices: • How to explain detections to stakeholders with confidence • How transparency helps analysts trust alerts — and act faster • What common mistakes teams make when relying on “black box” detections • How Hunt Hub fits into daily SOC and threat hunting workflows You’ll leave with a clear understanding of how Hunt Hub works in practice — not as a standalone tool, but as part of an intelligence-driven security approach — and how to apply this model both proactively and during live incident response. Register to see Hunt Hub in action — and learn directly from the experts who built it.
Kaspersky webinars

Kaspersky webinars

69648 subscribers286 talks
Latest on cyberthreats and protection technologies
On this channel, Kaspersky experts share their knowledge and key insights into high-fidelity threat hunting and intelligence, incident management, malware analysis, reverse engineering, security solutions, and several other vital aspects of the cyberworld. To keep you up to date, the experts also provide detailed webinars and workshops on how Kaspersky security solutions and services can halt and prevent a vast range of malicious attacks conducted by cybercriminals. Kaspersky is a global cybersecurity and digital privacy company that has been providing protection for 25 years, with over 400 million users from more than 200 countries. Kaspersky experts' mission is to help you find the perfect weapon to protect against any cyberthreat, carried out by even the most sophisticated cybercriminals. Kaspersky researchers are top-notch cybersecurity and protection technology experts, who regularly take part in leading information security events worldwide as best-in-class speakers. Kaspersky’s deep threat intelligence and security expertise is constantly being transformed into innovative security solutions and services that protect businesses, critical infrastructure, governments and consumers around the globe. Subscribe and learn more about the latest cybersecurity discoveries on the threat landscape and how to defend against them. Contact us at https://www.kaspersky.com/about/contact

Related topics