Don't just hunt threats.
DEFEAT them.

Hunt it. Fix it. Prove it.

DEFEAT is a threat-hunting methodology designed to carry the work past discovery. It connects the hunt to response, hardening, adversary emulation, automation, and long-term measurement.

DDiscover
EEradicate
FFortify
EEmulate
AAutomate
TTrack
See the lifecycle ↓

THE DEFEAT LIFECYCLE

Threat hunting should change the environment.

A hunt is not finished when the queries stop running. The useful end state is a better-defended environment with the reasoning, evidence, and validation preserved.

D01

Discover

Turn intelligence, hypotheses, and adversary behavior into a hunt plan grounded in ATT&CK and the telemetry actually available.

Produces Hunt plan + evidence requirements
E02

Eradicate

When malicious activity is confirmed, preserve investigative context while scoping, containing, and removing the threat.

Produces Scoped finding + response actions
F03

Fortify

Use what the hunt exposed to close detection, telemetry, configuration, and control gaps — including weaknesses that did not become incidents.

Produces Remediation + coverage improvements
E04

Emulate

Reproduce the relevant adversary behavior to verify that the changes made during the hunt detect, prevent, or constrain it as intended.

Produces Validation evidence
A05

Automate

Promote validated hunt logic into durable detections, enrichment, checks, and workflows where repeatability is justified.

Produces Reusable detection + workflow logic
T06

Track

Keep the lifecycle connected so teams can see what was hunted, what changed, what was tested, and where risk or coverage gaps remain.

Produces Measurable operational history

WHY DEFEAT

A hunt should not end with “hunt complete.”

The methodology treats hunting as a closed operational loop. Findings drive hardening. Hardening is tested. Validated logic becomes repeatable. The results stay measurable over time.

COMMON PATTERN Hunt → close
01StartThreat report or analyst hypothesis
→
02HuntRun queries and review hits
→
03FindingEscalate malicious activity
→
04CloseDocument results and move on
DEFEAT Hunt → improve
DDiscoverPlan against behavior, environment, and telemetry
→
EEradicateScope, contain, and preserve evidence
→
FFortifyClose detection and control gaps
→
EEmulateVerify the defense against the behavior
→
AAutomatePromote validated logic into repeatable defense
→
TTrackMeasure what changed and what remains

ONE CONTINUOUS RECORD

Keep the logic connected from intelligence to defense.

01Intelligencereport · IOC · behavior · hypothesis
→
02ATT&CKbehavior mapping · scope
→
03Hunt plandata source · query · expected signal
→
04Evidenceobservation · provenance · confidence
→
05Defensefix · validate · automate · track

CARACARAS.AI

Software to operationalize the methodology.

Caracaras is the platform being built around DEFEAT. The goal is to give threat-hunting teams one place to plan the hunt, preserve the evidence, manage what comes next, and prove whether defenses improved.

Product is currently in development.
01

Environment-aware hunt planning

Build the plan around the systems, data sources, and security tools the organization actually has.

02

Evidence and decision lineage

Keep observations, source material, analyst decisions, and supporting context tied to the hunt.

03

Remediation and validation

Carry findings into hardening and emulation instead of separating the hunt from the work it creates.

04

Repeatable defensive knowledge

Turn validated hunt logic into durable detections, workflows, and measurable coverage.

caracaras.ai

Hunt it. Fix it. Prove it.

Discover · Eradicate · Fortify · Emulate · Automate · Track