Detect APTs and zero-day attacks using CTI, behavioral analytics, and AI techniques
Gianluca Tiepolo, Dan Sorensen

#Cyber
#Threat
#Intelligence
#Hunting
#Attacks
#AI
#Behavioral_analytics
#APTs
#TTPs
Develop actionable strategies to proactively hunt advanced persistent threats and detect zero-days using CTI and behavior-based detection techniques
Modern adversaries rely on stealth, living-off-the-land techniques, and zero-day exploitation to evade traditional security controls. This practical guide shows experienced defenders how to move beyond reactive alerts and build a proactive threat hunting capability driven by cyber threat intelligence.
Written for seasoned cybersecurity professionals, the book demonstrates how to formulate CTI-driven hunt hypotheses and detect advanced persistent threats by analyzing adversary behavior across the Cyber Kill Chain. You’ll learn how to track APT infrastructure, map attacker TTPs using the MITRE ATT&CK framework, and identify post-exploitation activity that signals successful compromise.
Through hands-on exercises, you’ll apply behavioral analytics, detection engineering, and machine learning–based anomaly detection to uncover what signature-based tools miss. Coverage includes threat hunting in cloud, hybrid, and ICS/OT environments, with real-world techniques for lateral movement, persistence, privilege escalation, and data exfiltration.
By the end of this book, you’ll be equipped to run intelligence-led threat hunts, detect advanced threats earlier, and operationalize CTI as a core part of your defensive strategy.
This book is tailored for experienced, mid-to-senior level cybersecurity professionals operating in roles focused on proactive defense. The audience includes cyber threat hunters, cybersecurity analysts, cyber intelligence analysts, and incident responders. These profiles are looking to bridge the gap between intelligence production and its actionable application in live hunting operations, and this book will help them to achieve this.
Table of Contents
Part 1: Foundations of Cyber Threat Intelligence
1.Revisiting CTI for Advanced Threat Hunting
2.Understanding APTs – Actors, Motivations, and TTPs
3.Deep Dive – CTI Collection and Enrichment for APTs
Part 2: Advanced Threat Hunting
4.Core Principles of Proactive Threat Hunting
5.Understanding Data Sources for Threat Hunting
6.Hunting Zero-Days Through Behavioral Signatures
7.Advanced Hunting Techniques and Queries
Part 3: Practical APT Hunting Across the Cyber Kill Chain
8.Hunting Delivery and Initial Access
9.Hunting for Exploitation and Execution
10.Hunting for Persistence and Privilege Escalation
11.Hunting for Lateral Movement and Discovery
12.Hunting for Command and Control
13.Hunting for Collection, Exfiltration, and Impact
Part 4: Advanced Topics and Future Trends
14.Attribution – Challenges and Techniques
15.Behavioral Clustering for Zero-Day Detection
16.Hunting in Cloud and Specialized Environments
17.Building a Resilient Threat Hunting Program
18.Emerging Trends in Threat Hunting and CTI
“This book should be the go-to resource for anything related to Cyber Threat Intelligence and Hunting.”
Seetal Patel, Cybersecurity Specialist - Identity & Zero Trust
Gianluca Tiepolo is a cybersecurity researcher who specializes in mobile forensics and incident response. He holds a BSc degree in Computer Science and an MSc in Information Security, as well as several security-related certifications. Over the past 12 years, he has performed security monitoring, threat hunting, incident response, and intelligence analysis as a consultant for dozens of organizations, including several Fortune 100 companies. Gianluca is also the co-founder of the startup Sixth Sense Solutions, which developed AI-based anti-fraud solutions. Today, Gianluca works as a Security Delivery Team Lead for consulting firm Accenture Security. In 2016, he authored the book Getting Started with RethinkDB, published by Packt Publishing.
Dan Sorensen has a vast experience as a Chief Information Security Officer (CISO) and advisor. He has directed $50M+ cybersecurity programs, briefed boards and senior leaders, and delivered results that align security with business outcomes. His work spans cyber risk management, Zero Trust, FedRAMP/CMMC, IAM/PAM, and compliance with global frameworks including NIST RMF, ISO 27001, HIPAA, PCI-DSS, and the EU AI Act. He has guided organizations through digital transformation, regulatory change, and emerging threats, transforming risk posture with AI-driven solutions and measurable ROI.









