TC 3-12.2.98 governs defensive cyber force hunt operations within defensive cyberspace operations and the DOD network.
View TC 3-12.2.98 on armypubs.army.mil
TC 3-12.2.98 covers hunt methodology, threat analysis, operational environment shaping, command and control, security operations, and sustainment. It provides a framework and states that its tactics, techniques, and procedures are intended as a guide and are not prescriptive.
Applies to: This publication applies to the Active Army, Army National Guard/Army National Guard of the United States and United States Army Reserve unless otherwise stated.
Hunt is a tactical mission task undertaken in friendly controlled or contested cyberspace to identify and characterize threat presence and activity on the network. (paragraph 1-6)
Hunt operations enable offensive and defensive cyberspace operations, DODIN operations, and influence operations. (paragraph 1-3)
The various actors in any area of operations can qualify as threat, neutral, or friendly. (paragraph 3-1)
The defensive cyber force conducts threat research, collects data, renders information, and leverages intelligence to characterize and develop situational understanding of threat behavior in cyberspace, including Windows enterprise networks. (paragraph 2-3)
Characterization of malicious activity starts with developing or updating the generic adversary model of behavior to identify all tactics, techniques, and procedures a threat may useregardless of which threat group, environment, or targeted network. (paragraph 2-2)