WS4 - Agentic Threat Hunting: Building AI That Remembers What You Hunted
Description
Instructed by: Sydney “letswastetime” Marrone
Level of Difficulty: Intermediate, Advanced
Abstract:
Attendees hunt a supply chain compromise in real telemetry. Not a walkthrough - a hunt. A trojanized developer tool has been backdoored. The artifacts are seeded across a shared Splunk instance at layered difficulty: some obvious, some buried. Over four hours, attendees progress through the Five Levels of Agentic Hunting using the open-source Agentic Threat Hunting Framework (ATHF). Each maturity level unlocks new capabilities; structure, searchability, AI research agents, and full agentic workflows - that help them find what they couldn't find before.
The first hunt is manual. By the last module, AI agents are surfacing hypotheses, identifying coverage gaps, and pointing hunters toward artifacts they missed. The human decides what to chase. The framework remembers what they found.
This is not a tool demo. Attendees will make real analytical decisions, write real SPL queries, hit dead ends, and use AI agents to recover. They leave with a working ATHF workspace, documented hunts from a real investigation, and the experience of hunting with an agentic system.
Pre-Requisites:
· Laptop with Python 3.8+ installed
· pip install agentic-threat-hunting-framework completed before arrival
· At least one working LLM API key (any provider: OpenAI, Anthropic, AWS Bedrock, Ollama, or any OpenAI-compatible endpoint)
· A text editor or IDE
· Basic familiarity with threat hunting concepts, MITRE ATT&CK, and SPL (Splunk Search Processing Language)
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


