Welcome to the HEARTH community! We're excited to have you join us in building a comprehensive knowledge base for threat hunting. This guide will walk you through the process of submitting your hunt ideas and becoming an active member of our community.
Before submitting, ensure your hunt idea is well-thought-out and ready for review. Consider:
- What specific threat or behavior are you trying to detect?
- What data sources and tools are needed?
- How would others implement this hunt?
-
Go to Submit New Issue
-
Select "HEARTH Hunt Submission Form" template
-
Complete all required fields:
Core Information:
- Hunt Type 🔥
- Flames (Hypothesis-Driven): Based on assumptions about adversary behavior
- Embers (Baseline): Focused on identifying deviations from typical behavior
- Alchemy (Model-Assisted): Leveraging models like anomaly detection and machine learning
- HEARTH Crafter (your name/handle)
- Hunt Idea/Hypothesis
- MITRE ATT&CK Tactic
- Search Tags (e.g., #Persistence #WindowsEvents #ScheduledTasks)
Detailed Sections:
-
Implementation Notes
- Required data sources
- System requirements
- Technical limitations
- Key assumptions
-
Why Light This Fire? 🔥
- Security risks addressed
- Potential impact of findings
- Connection to threat campaigns
- Value to the community
-
Knowledge Base
- MITRE ATT&CK references
- Related research
- Supporting documentation
- Similar techniques
- Relevant tools/frameworks
- Hunt Type 🔥
-
Click "Submit new issue"
All submissions are reviewed by HEARTH Keepers who will:
- Verify technical accuracy and completeness
- Ensure proper documentation
- Provide feedback if needed
- Assign an official hunt number upon approval
Official hunt numbers are assigned based on the type:
- Flames (Hypothesis-Driven): H0001, H0002, H0003, etc.
- Embers (Baseline): B0001, B0002, B0003, etc.
- Alchemy (Model-Assisted): A0001, A0002, A0003, etc.
Upon approval, contributors receive:
- An official hunt number
- Community recognition
- Integration into the HEARTH repository
- Opportunity to collaborate with other hunters
If your hunt idea isn't fully developed yet:
- Check out The Forge for work-in-progress hunts
- Review existing hunts for inspiration
- Join community discussions
- Ask questions in our issues section
- Check out our 🪵 Resources Guide!
Remember: Every great hunt starts with a single idea. We're here to help you develop and share yours with the community.
Happy Hunting! 🔥