Threat Hunting with Python & Pandas @FIRSTdotorg
Threat Hunting with Python & Pandas  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 1 hour ago
Anthony Talamantes (Johns Hopkins University Applied Physics Laboratory, US), Matt Dulle (Johns Hopkins University Applied Physics Laboratory, US)

Anthony has over 24 years of experience in cybersecurity and the last 17 years focused on nation state and sophisticated adversaries. Anthony developed the Cyber Hunt program at Johns Hopkins Applied Physics Laboratory and current manages the Cyber Hunt, Applied Cyber Research, and Architecture & Engineering.

Matt has over 13 years of experience in cybersecurity and is the Lead Reverse Engineer in the Applied Cyber Research team at Johns Hopkins Applied Physics Lab. Matt performs malware analysis and uses behavioral indicators to proactively hunt for malicious activity in the enterprise.
--
This presentation will discuss some of the limitations with traditional SIEM’s and how cybersecurity is evolving away from them. We continue to describe threat hunting and detection engineering with a more iterative and scalable methodology than typically used with traditional SIEM’s. We will be examining the use of Python, Pandas, and other libraries in Jupyter notebooks to gain additional visibility and analyses into adversarial activities. We will demonstrate how this approach can work in cyber operations and give examples of the entire process including code examples. We will wrap up by discussing how this can be achievable by analysts without python and data science backgrounds.
Threat Hunting with Python & PandasEpisode 56: Mor Weinberger and Lior Kaplan, FIRSTCON26 SpeakersBuilding a Regional ISAC for West Africa that Works: Governance, Tools and Community MaturityThe EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...Chaos Stack: Designing Layered Tabletop Exercises for Complex Crisis Simulation99 Bottles of Trust on the Wall: Approaches to Building Convivial CommunitiesEverything Everywhere All at Once…in 2038Understanding Scammer Threats: Detection Strategies Aligned with Thailand’s Cybersecurity Act 2562CTI-Transmute: Harmonizing Threat Intelligence in a Multi-Standard EcosystemAccuracy Is Not Enough: Detecting Hidden Risk in CVE Impact PredictionIntroducing StealerLens: An LLM-Powered Forensics Microscope to Accelerate InfoStealer ...Itinerary to Defeat Yet Another Beacon Implementation
FIRST |

Threat Hunting with Python & Pandas

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER