M3HT4 EMULATIONS

See the behavior.
Follow the evidence.

Curated security research that follows attacker behavior into the telemetry, evidence, detections, and defender decisions it produces. Use the catalog for direct access to a specific emulation, or browse the Scenario Library when you want to explore.

EMULATION CATALOG

Start with the behavior you want to understand.

Foundations lead into techniques, detections, attack chains, and CVE studies. Search by subject or filter by platform and status to get to the right material quickly.

PREFER TO BROWSE?

Open the full Scenario Library.

Use the library when you want to compare available scenarios before opening one.

Scenario Library →
STRUCTURE

Behavior is the backbone.

CVE studies attach to reusable behaviors and evidence instead of becoming isolated one-off pages.

Foundations

Core host, identity, file, DNS, process, and network behaviors that later content can reuse.

Techniques

ATT&CK-aligned behavior studied independently of any one vulnerability.

Detections

Defender-focused material built around the telemetry needed to see and reason about behavior.

Attack chains

Multi-stage scenarios that combine earlier building blocks into a coherent sequence.

CVE studies

Curated vulnerability case studies that reuse the same behavior, telemetry, evidence, and detection model.

LEARNING PATHS

A clear place to start.

Paths guide newer users through the same catalog without forcing experienced practitioners into a fixed sequence.

In development

Start with Linux

Build from host and network visibility toward techniques, detections, attack chains, and CVE studies.

Planned

Start with Windows

Learn Windows execution, identity, services, scheduled activity, and the detections built around them.

Planned

Detection fundamentals

Work from required telemetry to observed evidence and practical detection reasoning.

COLLECTIONS

Related work, grouped when it helps.

Collections make it easier to follow a subject across multiple emulations without changing the underlying learning structure.

In development

Web intrusion

Content related to public-facing services, execution, discovery, network behavior, and defender visibility.

SCENARIO LIBRARY + REPLAY

Browse broadly, or go straight to the scenario.

The Scenario Library remains the main browse experience. When you select a specific emulation from this catalog, M3HT4 takes you directly into that scenario instead of asking you to choose it again.

Existing interactive routes stay intact.

The working Platform Beta and dedicated scenario replay pages are not being moved or rewritten by this update.

Browse Scenario Library →
RESPONSIBLE RESEARCH

The public site is not the lab.

Published material remains selected, sanitized, and separated from private operational details. M3HT4 research is limited to owned or explicitly authorized environments.

M3HT4 MODERN HUNTING TERRAIN
INDEPENDENT PROJECT SUPPORT

Keep the terrain
moving.

Voluntary support helps fund the infrastructure, research, tooling, and public learning experiences behind M3HT4.

Research Tools Infrastructure

Support never buys access. It does not purchase influence, services, testing authorization, priority, or private M3HT4 material.

SUPPORT M3HT4

Choose what feels right.

Ko-fi checkout
Opening secure support panel Loading Ko-fi only after you choose Support.

Checkout is provided by Ko-fi and its payment partners. M3HT4 does not collect payment-card details through this website.