Catch the intrusion
before it reaches Domain Admin.
IOC Hunt by Defsecone watches processes, persistence, and Active Directory attack paths on every endpoint, then ships everything — plus syslog from your firewalls and network gear — into one correlated incident timeline.
One agent. One aggregator. One timeline.
IOC Hunt is built from three parts that work as one system — not three separate tools bolted together.
Watches every host, blocks nothing until you say so
Runs on workstations, servers, and domain controllers. Local detection and local blocking, tuned per category so sensitive hosts get stricter defaults.
- 13 independent detection categories, each with its own response level
- 20+ Active Directory attack techniques, mapped to MITRE ATT&CK
- Hash-based baselining survives renamed or relocated files
The aggregator doesn't just collect logs — it correlates them
Every agent ships its encrypted event stream to a central server over a certificate-pinned connection. Events are grouped by shared process, IP, or user within a rolling window and rendered as one incident.
- 90-second correlation window across endpoint, AD, and syslog events
- Cert-pinned transport, alerted on MITM interception attempts
- Fleet-wide policy pushed back to every agent, in one console
Roll out quietly, then enforce with confidence
New deployments start in Learning Mode so you can baseline what's normal before anything gets auto-blocked. Once clean, categories you mark for enforcement start killing processes and reverting changes automatically.
- Alert-only baseline window before any blocking is enabled
- Approve or reject flagged items straight from the dashboard
- Per-category graduation to blocking — never an all-or-nothing switch
One agent, thirteen watch categories.
Every category has an independent response level — log only, log and alert, or log, alert, and auto-block — so you can tune sensitivity per host role without turning the whole agent up or down.
Process monitoring
Flags suspicious child processes spawned by Office, browsers, and scripting hosts.
Registry run keys
Watches HKLM/HKCU Run and RunOnce for new persistence entries.
Startup folder
Detects new files dropped into user and ProgramData startup folders.
Service creation
Alerts when a new Windows service is installed outside a trusted publisher path.
Scheduled tasks
Detects new scheduled tasks via WMI the moment they're registered.
Network & admin shares
Inbound RDP, SMB, and WinRM plus C$ / ADMIN$ access from unfamiliar sources.
Config changes
User creation, group membership, and audit-policy edits pulled straight from the event log.
Sensitive file access
Mimikatz, procdump, ntdsutil, LSASS dumps, and hive saves — caught by name and behavior.
Enumeration commands
net user, nltest, dsquery, BloodHound, whoami /all — the recon that precedes an attack.
Failed logon bursts
Immediate email alert once repeated 4625s cross your configured threshold.
Non-office-hours access
Logons outside the schedule you set, correlated against idle time to cut noise.
USB & removable media
Scans new drives for autorun.inf and unsigned executables on insertion.
Webcam & microphone
Flags unexpected camera or mic access — a common signal of commodity spyware.
The aggregator doesn't just collect logs — it correlates them.
Every agent ships its encrypted event stream to a central server over a certificate-pinned connection. The server groups events by shared process, IP, or user within a rolling window and renders the whole chain as one incident, whether it started on a laptop or a firewall.
IOC Hunt agent
Runs on every workstation, server, and domain controller. Local detection, local blocking, local baseline.
Firewalls & network gear
Any device that speaks syslog — perimeter firewalls, switches, VPN concentrators, wireless controllers.
Central server
Ingests agent events + syslog on a shared timeline. Ships policy back down to endpoints; ships nothing back to network devices.
Correlated dashboard
Per-machine timelines, cross-machine incident graphs, and a single search across every source.
Fleet policy
Push response-level and office-hours changes to every agent from one console.
Syslog ingestion, on the same timeline as endpoint telemetry
Point any RFC 3164 / 5424 syslog source at the central server's aggregator, and its events get normalized alongside agent detections — so a blocked outbound connection at the firewall and a DCSync attempt on the DC show up in the same incident, not two separate consoles.
Purpose-built to give you confidence, not noise.
Every design decision in IOC Hunt is aimed at one thing: an analyst trusts what the console is telling them.
Fast baseline
Day-one learning mode observes before it ever blocks — no surprise outages on rollout.
Low noise
Hash-based whitelisting survives renamed or relocated files, so approvals stay approved.
Fully auditable
Every category is a readable YAML rule — nothing is a black box you have to trust blindly.
Response-ready
Graduate any category to auto-block independently, scoped by host role.
One timeline
Endpoint, Active Directory, and syslog events correlate into a single incident view.
Every category is a readable, editable rule.
No black box — the same YAML that ships with the default ruleset is what you edit when you tune sensitivity, scope a category to specific hosts, or add your own indicators.
Per-category scope
Bind a rule to a host role, OU, or individual asset without touching the rest of the ruleset.
Response is composable
log, alert, and kill_process stack independently — start log-only, add enforcement later.
Correlation window is explicit
Every rule declares the window used to group it with other events into one incident on the central server.
Roll out quietly. Enforce with confidence.
New deployments start in Learning Mode so you can baseline what's actually normal on your fleet before anything gets auto-blocked.
Baseline & learn
The agent captures a full snapshot of processes, services, tasks, and run keys, then observes for a configurable window — alerting only, never blocking.
Review & whitelist
Approve or reject flagged items straight from the toast notification or the dashboard's baseline tab — by hash, so renamed or relocated files stay covered.
Blocking mode
Once the baseline is clean, categories you've marked for enforcement start killing processes, disabling services, and reverting config changes automatically.
See it running in your environment.
Bring your own firewall logs and a handful of test endpoints — most teams have a live incident timeline running inside one call.
Request a demoRequest a demo or trial license
We'll walk through detection coverage for your environment and get an agent + central server running in your lab — usually inside one call.
- Live walkthrough of the incident correlation graph
- Trial license covering agents and one central server
- Guidance on syslog onboarding for your firewall stack
- No obligation — cancel the trial any time
Request received
Your request was sent to giri@defsecone.com. Someone from the IOC Hunt team will reach out within one business day to schedule your demo.