{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T10:44:12Z","timestamp":1786099452970,"version":"3.56.0"},"reference-count":21,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.comnet.2026.112630","type":"journal-article","created":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T16:10:52Z","timestamp":1785341452000},"page":"112630","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Security framework for threat hunting advanced adversaries for initial level access"],"prefix":"10.1016","volume":"288","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7361-0465","authenticated-orcid":false,"given":"Akashdeep","family":"Bhardwaj","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112630_bib0001","unstructured":"\u201cInitial access | red canary threat detection report,\u201d red canary, 2025. https:\/\/redcanary.com\/threat-detection-report\/trends\/initial-access\/(accessed Apr. 09, 2025)."},{"key":"10.1016\/j.comnet.2026.112630_bib0002","unstructured":"Fortinet, \u201cLateral movement: how to detect and prevent it,\u201d fortinet. https:\/\/www.fortinet.com\/resources\/cyberglossary\/lateral-movement."},{"key":"10.1016\/j.comnet.2026.112630_bib0003","unstructured":"Kaspersky, \u201cWhat is Spear Phishing?,\u201d Kaspersky.com, 2019. https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing."},{"key":"10.1016\/j.comnet.2026.112630_bib0004","unstructured":"MITRE, \u201cInitial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK\u00ae,\u201d attack.mitre.org, Oct. 17, 2018. https:\/\/attack.mitre.org\/tactics\/TA0001\/."},{"issue":"2","key":"10.1016\/j.comnet.2026.112630_bib0005","doi-asserted-by":"crossref","first-page":"12","DOI":"10.63180\/jcsra.thestap.2025.2.2","article-title":"Analyzing cybersecurity risks and threats in IT infrastructure based on NIST framework","volume":"2025","author":"Aljumaiah","year":"2025","journal-title":"J. Cyber Secur. Risk Audit."},{"key":"10.1016\/j.comnet.2026.112630_bib0006","series-title":"2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT)","first-page":"305","article-title":"Modeling features threats to the security of information in the process threat hunting","author":"Ponomareva","year":"2023"},{"issue":"6","key":"10.1016\/j.comnet.2026.112630_bib0007","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/IOTM.001.2400061","article-title":"Merging threat modeling with threat hunting for dynamic cybersecurity defense","volume":"7","author":"Nour","year":"2024","journal-title":"IEEE Internet Things Mag."},{"issue":"4","key":"10.1016\/j.comnet.2026.112630_bib0008","doi-asserted-by":"crossref","first-page":"2299","DOI":"10.1109\/COMST.2023.3299519","article-title":"A survey on threat hunting in enterprise networks","volume":"25","author":"Nour","year":"2023","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.comnet.2026.112630_bib0009","series-title":"2022 7th IEEE International Conference on Data Science in Cyberspace (DSC)","first-page":"340","article-title":"A survey on threat hunting: approaches and applications","author":"Chen","year":"2022"},{"key":"10.1016\/j.comnet.2026.112630_bib0010","series-title":"2024 IEEE 29th International Conference on Emerging Technologies and Factory Automation (ETFA)","first-page":"01","article-title":"GraphWatch: a novel threat hunting approach for APT activities based on anomaly detection","author":"Buchta","year":"2024"},{"key":"10.1016\/j.comnet.2026.112630_bib0011","series-title":"2021 International Conference on Electrical, Computer and Energy Technologies (ICECET)","first-page":"1","article-title":"Methods for automating threat hunting and response","author":"Adedoyin","year":"2021"},{"key":"10.1016\/j.comnet.2026.112630_bib0012","series-title":"2022 International Conference on Data Analytics for Business and Industry (ICDABI)","first-page":"309","article-title":"Zero-day attack solutions using threat hunting intelligence: extensive survey","author":"AlMahmeed","year":"2022"},{"key":"10.1016\/j.comnet.2026.112630_bib0013","series-title":"2021 2nd International Conference on Artificial Intelligence and Data Sciences (AiDAS)","first-page":"1","article-title":"Development of open source-based threat hunting platform","author":"Hermawan","year":"2021"},{"key":"10.1016\/j.comnet.2026.112630_bib0014","unstructured":"\u201cWhat Is SIEM? | Microsoft Security,\u201d www.microsoft.com. https:\/\/www.microsoft.com\/en-in\/security\/business\/security-101\/what-is-siem."},{"key":"10.1016\/j.comnet.2026.112630_bib0015","unstructured":"Elastic, \u201cElasticsearch: The Official Distributed Search & Analytics Engine,\u201d Elastic. https:\/\/www.elastic.co\/elasticsearch."},{"key":"10.1016\/j.comnet.2026.112630_bib0016","unstructured":"\u201cSpearphishing Attachment, Technique T0865 - ICS | MITRE ATT&CK\u00ae,\u201d attack.mitre.org. https:\/\/attack.mitre.org\/techniques\/T0865\/."},{"key":"10.1016\/j.comnet.2026.112630_bib0017","unstructured":"\u201cUbuntu Server - for scale out workloads | Ubuntu,\u201d Ubuntu, 2019. https:\/\/ubuntu.com\/server."},{"key":"10.1016\/j.comnet.2026.112630_bib0018","unstructured":"VMware, \u201cWhat is a Virtual Machine? | VMware Glossary,\u201d www.vmware.com. https:\/\/www.vmware.com\/topics\/virtual-machine."},{"key":"10.1016\/j.comnet.2026.112630_bib0019","unstructured":"\u201cKibana: Explore, Visualize, Discover Data,\u201d Elastic. https:\/\/www.elastic.co\/kibana."},{"key":"10.1016\/j.comnet.2026.112630_bib0020","unstructured":"\u201cLogstash: Collect, Parse, Transform Logs,\u201d Elastic. https:\/\/www.elastic.co\/logstash."},{"key":"10.1016\/j.comnet.2026.112630_bib0021","unstructured":"\u201cTry it,\u201d GitHub, Dec. 06, 2022. https:\/\/github.com\/TheHive-Project\/TheHive."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626006420?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626006420?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T09:51:11Z","timestamp":1786096271000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626006420"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":21,"alternative-id":["S1389128626006420"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112630","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Security framework for threat hunting advanced adversaries for initial level access","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112630","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112630"}}