TC 3-12.2.98 — Hunt Operations

TC 3-12.2.98 governs defensive cyber force hunt operations within defensive cyberspace operations and the DOD network.

Search TC 3-12.2.98

  • Publication number: TC 3-12.2.98
  • Title: HUNT OPERATIONS
  • Date: 02/02/2024
  • Proponent: T2COM
  • Status: ACTIVE

View TC 3-12.2.98 on armypubs.army.mil


TC 3-12.2.98 covers hunt methodology, threat analysis, operational environment shaping, command and control, security operations, and sustainment. It provides a framework and states that its tactics, techniques, and procedures are intended as a guide and are not prescriptive.

Applies to: This publication applies to the Active Army, Army National Guard/Army National Guard of the United States and United States Army Reserve unless otherwise stated.

Topics covered

  • Defensive cyber forces
  • Hunt methodology
  • Cyberspace actors and threat groups
  • Operational environment shaping
  • Command and control for hunt operations
  • Security operations
  • Hunt sustainment

Questions and answers

What is a hunt mission in cyberspace?

Hunt is a tactical mission task undertaken in friendly controlled or contested cyberspace to identify and characterize threat presence and activity on the network. (paragraph 1-6)

What operations do hunt operations enable?

Hunt operations enable offensive and defensive cyberspace operations, DODIN operations, and influence operations. (paragraph 1-3)

What actors can qualify as a threat in cyberspace?

The various actors in any area of operations can qualify as threat, neutral, or friendly. (paragraph 3-1)

How does the defensive cyber force characterize threat behavior?

The defensive cyber force conducts threat research, collects data, renders information, and leverages intelligence to characterize and develop situational understanding of threat behavior in cyberspace, including Windows enterprise networks. (paragraph 2-3)

What does characterization of malicious activity begin with?

Characterization of malicious activity starts with developing or updating the generic adversary model of behavior to identify all tactics, techniques, and procedures a threat may useregardless of which threat group, environment, or targeted network. (paragraph 2-2)

Ask Reggie.Bot a question about TC 3-12.2.98