Cybersecurity increasingly relies on threat hunters to proactively identify adversarial activity, yet the cognitive work underlying threat hunting remains underexplored or insufficiently supported by existing tools. Building on prior studies that examined how threat hunters construct and share mental models during investigations, we derived a set of design propositions to support their cognitive and collaborative work. In this paper, we present the Threat Hunter Board, a prototype tool that operationalizes these design propositions by enabling threat hunters to externalize reasoning, organize investigative leads, and maintain continuity across sessions. Using a design science paradigm, we describe the solution design rationale and artifact development. In addition, we propose six design heuristics that form a solution-evaluation framework for assessing cognitive support in threat hunting tools. An initial evaluation using a cognitive walkthrough provides early evidence of feasibility, while future work will focus on user-based validation with professional threat hunters.
Airdrops issued by platforms are to distribute tokens, drive user adoption, and promote decentralized services. The distributions attract airdrop hunters (attackers), who exploit the system by employing Sybil attacks, i.e., using multiple identities to manipulate token allocations to meet eligibility criteria. While debates around airdrop hunting question the potential benefits to the ecosystem, exploitative behaviors like Sybil attacks clearly undermine the system's integrity, eroding trust and credibility. Despite the increasing prevalence of these tactics, a gap persists in the literature regarding systematic modeling of airdrop hunters' costs and returns, alongside the theoretical models capturing the interactions among all roles for airdrop mechanism design. Our study first conducts an empirical analysis of transaction data from the Hop Protocol and LayerZero, identifying prevalent attack patterns and estimating hunters' expected profits. Furthermore, we develop a game-theory model that simulates the interactions between attackers, organizers, and bounty hunters, proposing optimal incentive structures that enhance detection while minimizing organizational costs.
Hunters and Rabbit game is played on a graph $G$ where the Hunter player shoots at $k$ vertices in every round while the Rabbit player occupies an unknown vertex and, if not shot, must move to a neighbouring vertex after each round. The Rabbit player wins if it can ensure that its position is never shot. The Hunter player wins otherwise. The hunter number $h(G)$ of a graph $G$ is the minimum integer $k$ such that the Hunter player has a winning strategy (i.e., allowing him to win whatever be the strategy of the Rabbit player). This game has been studied in several graph classes, in particular in bipartite graphs (grids, trees, hypercubes...), but the computational complexity of computing $h(G)$ remains open in general graphs and even in trees. To progress further, we propose a notion of monotonicity for the Hunters and Rabbit game imposing that, roughly, a vertex that has already been shot ``must not host the rabbit anymore''. This allows us to obtain new results in various graph classes. Let the monotone hunter number be denoted by $mh(G)$. We show that $pw(G) \leq mh(G) \leq pw(G)+1$ for any graph $G$ with pathwidth $pw(G)$, implying that computing $mh(G)$, or even approximating
Adversary emulation is an essential procedure for cybersecurity assessments such as evaluating an organization's security posture or facilitating structured training and research in dedicated environments. To allow for systematic and time-efficient assessments, several approaches from academia and industry have worked towards the automation of adversarial actions. However, they exhibit significant limitations regarding autonomy, tactics coverage, and real-world applicability. Consequently, adversary emulation remains a predominantly manual task requiring substantial human effort and security expertise - even amidst the rise of Large Language Models. In this paper, we present Bounty Hunter, an automated adversary emulation method, designed and implemented as an open-source plugin for the popular adversary emulation platform Caldera, that enables autonomous emulation of adversaries with multi-faceted behavior while providing a wide coverage of tactics. To this end, it realizes diverse adversarial behavior, such as different levels of detectability and varying attack paths across repeated emulations. By autonomously compromising a simulated enterprise network, Bounty Hunter showcases
This article introduces the Fuzzy Hunter Optimizer (FHO), a novel metaheuristic inspired by Lévy diffuse visibility walk observed in predatory species and even in human behavior during the search for sustenance. To address a constrained optimization problem, we initialize a population of hunters in the search space. The hunter with the best fitness represents the food source. The other hunters move through the search space following a Lévy walk. When they spot the food source, they move towards it, gradually abandoning the Levy walk. To model the hunters visibility, we employ linear membership functions. In each iteration, the hunter with the best fitness becomes the food source. Unlike other metaheuristics, FHO parameters (visibility functions) do not require pre-calibration, since they adapt with iterations.
With security threats increasing in frequency and severity, it is critical that we consider the important role of threat hunters. These highly-trained security professionals learn to see, identify, and intercept security threats. Many recent works and existing tools in cybersecurity are focused on automating the threat hunting process, often overlooking the critical human element. Our study shifts this paradigm by emphasizing a human-centered approach to understanding the lived experiences of threat hunters. By observing threat hunters during hunting sessions and analyzing the rich insights they provide, we seek to advance the understanding of their cognitive processes and the tool support they need. Through an in-depth observational study of threat hunters, we introduce a model of how they build and refine their mental models during threat hunting sessions. We also present 23 themes that provide a foundation to better understand threat hunter needs and suggest five actionable design propositions to enhance the tools that support them. Through these contributions, our work enriches the theoretical understanding of threat hunting and provides practical insights for designing more ef
We present a novel, deep-learning based method -- dubbed Galactic-Seismology Substructures and Streams Hunter, or GS$^{3}$ Hunter for short, to search for substructures and streams in stellar kinematics data. GS$^{3}$ Hunter relies on a combined application of Siamese Neural Networks to transform the phase space information and the K-means algorithm for the clustering. As a validation test, we apply GS$^{3}$ Hunter to a subset of the Feedback in Realistic Environments (FIRE) cosmological simulations. The stellar streams and substructures thus identified are in good agreement with corresponding results reported earlier by the FIRE team. In the same vein, we apply our method to a subset of local halo stars from the Gaia Early Data Release 3 and GALAH DR3 datasets, and recover several, previously known dynamical groups, such as Thamnos 1+2, Hot Thick Disk, ED-1, L-RL3, Helmi 1+2, and Gaia-Sausage-Enceladus, Sequoia, VRM, Cronus, Nereus. Finally, we apply our method without fine-tuning to a subset of K-giant stars located in the inner halo region, obtained from the LAMOST Data Release 5 (DR5) dataset. We recover three, previously known structures (Sagittarius, Hercules-Aquila Cloud, an
Hunter proved that the complete homogeneous symmetric polynomials of even degree are positive definite. We prove a noncommutative generalization of this result, in which the scalar variables are replaced with hermitian operators. We provide a sharp lower bound and a sum of hermitian squares representation that are novel even in the scalar case.
We rigorously construct a family of smooth self-similar solutions to the isentropic gravitational Euler-Poisson system with a polytropic equation of state for polytropic indices lying in the full energy-supercritical range, $1<γ<\frac{6}{5}$. The result is an extension of the author's previous construction of Hunter solutions in the isothermal case, $γ=1$, and complements a construction of Larson-Penston-type solutions by Guo-Hadžić-Jang-Schrecker for the same system in the full mass-supercritical range, $1<γ<\frac{4}{3}$. As an ingredient in the proof, a general framework is introduced for proving local analyticity of solutions to this system in the vicinity of singular points. This framework could be used for other quasilinear self-similar blow-up constructions.
We present GS3 Hunter (Galactic-Seismology Substructures and Streams Hunter), a novel deep-learning method that combines Siamese Neural Networks and K-means clustering to identify substructures and streams in stellar kinematic data. Applied to Gaia EDR3 and GALAH DR3, it recovers known groups (e.g., Thamnos, Helmi, GSE, Sequoia) and, with DESI dataset, reveals that GSE consists of four distinct components (GSH-GSH1 through GSE-GSH4), implying a multi-event accretion origin. Tests on LAMOST K-giants recover Sagittarius, Hercules-Aquila, and Virgo Overdensity, while also uncovering new substructures. Validation with FIRE simulations shows good agreement with previous results. GS3 Hunter thus offers a powerful tool to understand the Milky Way's halo assembly and tidal history.
Although researchers have characterized the bug-bounty ecosystem from the point of view of platforms and programs, minimal effort has been made to understand the perspectives of the main workers: bug hunters. To improve bug bounties, it is important to understand hunters' motivating factors, challenges, and overall benefits. We address this research gap with three studies: identifying key factors through a free listing survey (n=56), rating each factor's importance with a larger-scale factor-rating survey (n=159), and conducting semi-structured interviews to uncover details (n=24). Of 54 factors that bug hunters listed, we find that rewards and learning opportunities are the most important benefits. Further, we find scope to be the top differentiator between programs. Surprisingly, we find earning reputation to be one of the least important motivators for hunters. Of the challenges we identify, communication problems, such as unresponsiveness and disputes, are the most substantial. We present recommendations to make the bug-bounty ecosystem accommodating to more bug hunters and ultimately increase participation in an underutilized market.
Change point detection has recently gained popularity as a method of detecting performance changes in software due to its ability to cope with noisy data. In this paper we present Hunter, an open source tool that automatically detects performance regressions and improvements in time-series data. Hunter uses a modified E-divisive means algorithm to identify statistically significant changes in normally-distributed performance metrics. We describe the changes we made to the E-divisive means algorithm along with their motivation. The main change we adopted was to replace the significance test using randomized permutations with a Student's t-test, as we discovered that the randomized approach did not produce deterministic results, at least not with a reasonable number of iterations. In addition we've made tweaks that allow us to find change points the original algorithm would not, such as two nearby changes. For evaluation, we developed a method to generate real timeseries, but with artificially injected changes in latency. We used these data sets to compare Hunter against two other well known algorithms, PELT and DYNP. Finally, we conclude with lessons we've learned supporting Hunter
A theorem of Hunter ensures that the complete homogeneous symmetric polynomials of even degree are positive definite functions. A probabilistic interpretation of Hunter's theorem suggests a broad generalization: the construction of so-called random vector norms on square complex matrices. This paper surveys these ideas, starting from the fundamental notions and developing the theory to its present state. We study numerous examples and present a host of open problems.
We consider a variation of a cops and robbers game in which the cop---here referred to as "hunter"---is not constrained by the graph but must play in the dark against a "mole." We characterize the graphs---which we will call "hunter-win"---on which the hunter can guarantee capture of the mole in bounded time. We also define an optimal hunter strategy (and consequently an upper bound on maximum game time on hunter-win graphs) and note that an optimal hunter strategy need not take advantage of the hunter's unconstrained movement! This game comes from a puzzle of unknown origin which was told to the authors by Dick Hess.
Nowadays, blockchain-based technologies are being developed in various industries to improve data security. In the context of the Industrial Internet of Things (IIoT), a chain-based network is one of the most notable applications of blockchain technology. IIoT devices have become increasingly prevalent in our digital world, especially in support of developing smart factories. Although blockchain is a powerful tool, it is vulnerable to cyber attacks. Detecting anomalies in blockchain-based IIoT networks in smart factories is crucial in protecting networks and systems from unexpected attacks. In this paper, we use Federated Learning (FL) to build a threat hunting framework called Block Hunter to automatically hunt for attacks in blockchain-based IIoT networks. Block Hunter utilizes a cluster-based architecture for anomaly detection combined with several machine learning models in a federated environment. To the best of our knowledge, Block Hunter is the first federated threat hunting model in IIoT networks that identifies anomalous behavior while preserving privacy. Our results prove the efficiency of the Block Hunter in detecting anomalous activities with high accuracy and minimum r
Residential mobility is deeply entangled with all aspects of hunter-gatherer life ways, and is therefore an issue of central importance in hunter-gatherer studies. Hunter-gatherers vary widely in annual rates of residential mobility, and understanding the sources of this variation has long been of interest to anthropologists and archaeologists. Since mobility is, to a large extent, driven by the need for a continuous supply of food, a natural framework for addressing this question is provided by the metabolic theory of ecology. This provides a powerful framework for formulating formal testable hypotheses concerning evolutionary and ecological constraints on the scale and variation of hunter-gatherer residential mobility. We evaluate these predictions using extant data and show strong support for the hypotheses. We show that the overall scale of hunter-gatherer residential mobility is predicted by average human body size, and the limited capacity of mobile hunter-gatherers to store energy internally. We then show that the majority of variation in residential mobility observed across cultures is predicted by energy availability in local ecosystems. Our results demonstrate that large-
The hunter and gatherer approach copes with the problem of dynamic multi-robot task allocation, where tasks are unknowingly distributed over an environment. This approach employs two complementary teams of agents: one agile in exploring (hunters) and another dexterous in completing (gatherers) the tasks. Although this approach has been studied from the task planning point of view in our previous works, the multi-robot exploration and coordination aspects of the problem remain uninvestigated. This paper proposes a multi-robot exploration algorithm for hunters based on innovative notions of "expected information gain" to minimize the collective cost of task accomplishments in a distributed manner. Besides, we present a coordination solution between hunters and gatherers by integrating the novel notion of profit margins into the concept of expected information gain. Statistical analysis of extensive simulation results confirms the efficacy of the proposed algorithms compared in different environments with varying levels of obstacles complexities. We also demonstrate that the lack of effective coordination between hunters and gatherers significantly hurts the total effectiveness of the
We present novel geometric numerical integrators for Hunter--Saxton-like equations by means of new multi-symplectic formulations and known Hamiltonian structures of the problems. We consider the Hunter--Saxton equation, the modified Hunter--Saxton equation, and the two-component Hunter--Saxton equation. Multi-symplectic discretisations based on these new formulations of the problems are exemplified by means of the explicit Euler box scheme, and Hamiltonian-preserving discretisations are exemplified by means of the discrete variational derivative method. We explain and justify the correct treatment of boundary conditions in a unified manner. This is necessary for a proper numerical implementation of these equations and was never explicitly clarified in the literature before, to the best of our knowledge. Finally, numerical experiments demonstrate the favourable behaviour of the proposed numerical integrators.
It is shown that two different supersymmetric extensions of the Harry Dym equation lead to two different negative hierarchies of the supersymmetric integrable equations. While the first one yields the known even supersymmetric Hunter - Saxton equation, the second one is a new odd supersymmetric Hunter - Saxton equation. It is further proved that these two supersymmetric extensions of the Hunter - Saxton equation are reciprocally transformed to two different supersymmetric extensions of the Liouville equation.
We present the results from a search of data from the first 33.5 days of the Kepler science mission (Quarter 1) for exoplanet transits by the Planet Hunters citizen science project. Planet Hunters enlists members of the general public to visually identify transits in the publicly released Kepler light curves via the World Wide Web. Over 24,000 volunteers reviewed the Kepler Quarter 1 data set. We examine the abundance of \geq 2 R\oplus planets on short period (< 15 days) orbits based on Planet Hunters detections. We present these results along with an analysis of the detection efficiency of human classifiers to identify planetary transits including a comparison to the Kepler inventory of planet candidates. Although performance drops rapidly for smaller radii, \geq 4 R\oplus Planet Hunters \geq 85% efficient at identifying transit signals for planets with periods less than 15 days for the Kepler sample of target stars. Our high efficiency rate for simulated transits along with recovery of the majority of Kepler \geq 4 R\oplus planets suggest suggests the Kepler inventory of \geq 4 R\oplus short period planets is nearly complete.