<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Threat Hunting</title><description>Cybersecurity articles tagged #Threat Hunting on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Powered Malware Analysis: Detecting Persistent Threats on Sensors</title><link>https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</guid><description>An analysis using Gemma4 with Ollama reveals high-volume malware downloads on DShield sensors, indicating persistent actor activity and critical compromise risks.</description><pubDate>Thu, 13 Aug 2026 09:04:55 GMT</pubDate><category>AI</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Botnet</category><category>Cowrie Sensor</category></item><item><title>Navigating the Hunter&apos;s Paradox: AI in Threat Hunting</title><link>https://runtimerebel.com/blog/navigating-the-hunter-s-paradox-ai-in-threat-hunting</link><guid isPermaLink="true">https://runtimerebel.com/blog/navigating-the-hunter-s-paradox-ai-in-threat-hunting</guid><description>Explore the Hunter&apos;s Paradox, where human limits in threat hunting meet AI&apos;s trust issues, and redefine hunting for an AI-driven future.</description><pubDate>Sat, 08 Aug 2026 08:31:47 GMT</pubDate><category>Threat Hunting</category><category>Artificial Intelligence</category><category>AI in Security</category><category>Cybersecurity Operations</category><category>Security Analytics</category></item><item><title>Cyber Threat Hunting: A Strategic Intelligence Guide</title><link>https://runtimerebel.com/blog/cyber-threat-hunting-a-strategic-intelligence-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyber-threat-hunting-a-strategic-intelligence-guide</guid><description>Master modern cyber threat hunting by embracing real-time threat intelligence. This guide covers methodologies, tools, and frameworks for proactive adversary detection.</description><pubDate>Mon, 20 Jul 2026 18:07:35 GMT</pubDate><category>Threat Hunting</category><category>Threat Intelligence</category><category>Cybersecurity Strategy</category><category>Proactive Defense</category><category>MITRE ATT CK</category></item><item><title>Beacon Security Secures $13M to Scale Security Data Platform</title><link>https://runtimerebel.com/blog/beacon-security-secures-13m-to-scale-security-data-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/beacon-security-secures-13m-to-scale-security-data-platform</guid><description>Beacon Security raises $13 million in seed funding to help organizations detect and hunt assets at machine speed by eliminating security data silos.</description><pubDate>Fri, 17 Jul 2026 13:53:26 GMT</pubDate><category>Beacon Security</category><category>Security Data Platform</category><category>Threat Hunting</category><category>Ballistic Ventures</category></item><item><title>YARA-X 1.18.0 &amp; 1.19.0 Release: Enhancing Malware Detection</title><link>https://runtimerebel.com/blog/yara-x-1-18-0-1-19-0-release-enhancing-malware-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-18-0-1-19-0-release-enhancing-malware-detection</guid><description>YARA-X versions 1.18.0 and 1.19.0 bring key improvements and bug fixes, enhancing malware analysis and threat hunting capabilities for security professionals.</description><pubDate>Sun, 28 Jun 2026 09:09:21 GMT</pubDate><category>YARA X</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Security Tools</category><category>Version Update</category></item><item><title>AI-Native Contextual Security: Nebulock&apos;s $25M Funding Impact</title><link>https://runtimerebel.com/blog/ai-native-contextual-security-nebulock-s-25m-funding-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-native-contextual-security-nebulock-s-25m-funding-impact</guid><description>Nebulock secures $25M for AI-native contextual security, emphasizing advanced threat hunting, proactive detection, and behavioral analytics capabilities.</description><pubDate>Fri, 26 Jun 2026 12:51:49 GMT</pubDate><category>AI Native Security</category><category>Contextual Security</category><category>Threat Hunting</category><category>Behavioral Analytics</category><category>Nebulock</category></item><item><title>YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis</title><link>https://runtimerebel.com/blog/yara-x-1-17-0-release-enhanced-performance-for-malware-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-17-0-release-enhanced-performance-for-malware-analysis</guid><description>YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.</description><pubDate>Sun, 31 May 2026 16:31:57 GMT</pubDate><category>YARA X</category><category>Malware Detection</category><category>Rust</category><category>Threat Hunting</category><category>SANS ISC</category></item><item><title>YARA-X 1.16.0 Release: Performance Gains for Malware Detection</title><link>https://runtimerebel.com/blog/yara-x-1-16-0-release-performance-gains-for-malware-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-16-0-release-performance-gains-for-malware-detection</guid><description>YARA-X 1.16.0 introduces key improvements and bugfixes for the Rust-based pattern matching engine. Explore how these updates optimize malware detection.</description><pubDate>Mon, 11 May 2026 00:53:57 GMT</pubDate><category>YARA X</category><category>Malware Detection</category><category>Rust Security</category><category>Threat Hunting</category><category>Open Source Tools</category></item><item><title>Detecting Malicious msiexec Remote Payload Execution via SIEM Logs</title><link>https://runtimerebel.com/blog/detecting-malicious-msiexec-remote-payload-execution-via-siem-logs</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-malicious-msiexec-remote-payload-execution-via-siem-logs</guid><description>Analyze how attackers abuse Windows Installer (msiexec.exe) to fetch remote payloads and learn technical strategies for detection and mitigation.</description><pubDate>Tue, 05 May 2026 05:08:51 GMT</pubDate><category>Msiexec</category><category>LoLBins</category><category>Windows Installer</category><category>Threat Hunting</category><category>Detection Engineering</category></item><item><title>AI Digital Twin Security Implementation for Enterprise Threat Hunting</title><link>https://runtimerebel.com/blog/ai-digital-twin-security-implementation-for-enterprise-threat-hunting</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-digital-twin-security-implementation-for-enterprise-threat-hunting</guid><description>JPMorgan Chase uses digital twins and fingerprints to model 300,000 users, reducing false positives and automating detection in high-volume environments.</description><pubDate>Tue, 24 Mar 2026 16:30:30 GMT</pubDate><category>AI Security</category><category>Threat Hunting</category><category>Jpmorgan Chase</category><category>Digital Twins</category><category>Machine Learning</category></item><item><title>YARA-X 1.14.0 Release: Enhanced Performance and Module Stability</title><link>https://runtimerebel.com/blog/yara-x-1-14-0-release-enhanced-performance-and-module-stability</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-14-0-release-enhanced-performance-and-module-stability</guid><description>The YARA-X 1.14.0 release introduces critical module improvements and bug fixes to optimize high-performance malware scanning and threat detection.</description><pubDate>Sat, 07 Mar 2026 12:39:11 GMT</pubDate><category>YARA X</category><category>Malware Detection</category><category>Virustotal</category><category>Threat Hunting</category><category>Rust</category></item><item><title>Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth</title><link>https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</link><guid isPermaLink="true">https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</guid><description>Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.</description><pubDate>Thu, 26 Feb 2026 04:39:45 GMT</pubDate><category>Persistence Mechanisms</category><category>EDR Evasion</category><category>Virtualization Abuse</category><category>Threat Hunting</category><category>SANS ISC</category></item><item><title>Optimizing Honeypot Log Analysis Using AI and LLM Orchestration</title><link>https://runtimerebel.com/blog/optimizing-honeypot-log-analysis-using-ai-and-llm-orchestration</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-honeypot-log-analysis-using-ai-and-llm-orchestration</guid><description>An analysis of how AI-assisted log processing reduces noise in DShield and Cowrie honeypot data, enabling analysts to identify sophisticated threat patterns.</description><pubDate>Thu, 26 Feb 2026 04:39:18 GMT</pubDate><category>AI ML</category><category>Honeypots</category><category>Cowrie</category><category>DShield</category><category>Log Analysis</category><category>Threat Hunting</category></item></channel></rss>