# Focused Hunts > Focused Hunts is a cybersecurity consulting firm specializing in defense validation, threat hunting, and security advisory services. Founded by Joe Schumacher, the company provides independent security assurance through hypothesis-driven threat hunts, purple team exercises, and defense validation engagements. ## About Focused Hunts operates as an independent security advisor with over 20 years of cybersecurity experience. The firm verifies that security defenses work as intended through proactive testing, customized assessments, and advanced threat intelligence. Services are vendor-neutral and tailored to each client's security stack and risk tolerance. ## Services - **Defense Validation**: Independent verification that security controls detect and respond to real threats. Includes configuration review, detection gap analysis, and control assurance. - **Threat Hunting**: Hypothesis-driven hunts tailored to real-world threats. Proactive investigation beyond alert-based monitoring to find threats that don't trigger alerts. - **Purple Team Exercises**: Collaborative offensive-defensive exercises that test detection and response capabilities against realistic attack scenarios. ## Products - **The Vault**: A privacy-first password manager using Bring Your Cloud (BYC) storage. Encrypts data on-device with AES-256-GCM and Argon2id key derivation. Syncs through user-owned cloud storage (Google Drive, OneDrive). Available on Windows and Android. Currently in open beta. - **Prompt Intelligence** (Book): An AI framework for security professionals. Teaches systematic AI interaction using four principles: Context is King, Specificity Drives Accuracy, Structure Enables Clarity, and Iteration Reveals Truth. By Joe Schumacher. Available on Amazon and Ingram Sparks. - **Beyond the Pilot** (Book): AI in Security Operations. A framework for implementing AI in security operations, covering agentic autonomy, model agnosticism, and the amplification model. By Joe Schumacher. Available on Amazon. ## Blog Articles (Executive Series) Strategic perspectives on threat hunting, defense validation, and proactive security for executives and security leaders. - [Stop Asking Your Reactive SOC to Be Proactive](https://www.focusedhunts.com/blog/articles/Stop-Asking-Your-Reactive-SOC-to-Be-Proactive) - TOM Series Part 6 (March 30, 2026) - [Five Questions Your MSSP Can't Answer](https://www.focusedhunts.com/blog/articles/Five-Questions-Your-MSSP-Cant-Answer) - TOM Series Part 5 (March 17, 2026) - [The Hybrid Model: Monitoring and Hunting Together](https://www.focusedhunts.com/blog/articles/The-Hybrid-Model-Monitoring-and-Hunting) - TOM Series Part 4 (March 3, 2026) - [Paying for Coverage You Don't Need: The Continuous Hunting Myth](https://www.focusedhunts.com/blog/articles/Paying-for-Coverage-The-Continuous-Hunting-Myth) - TOM Series Part 3 (February 17, 2026) - [Your MSSP's Operating Model Hasn't Kept Up](https://www.focusedhunts.com/blog/articles/Your-MSSPs-Operating-Model-Hasnt-Kept-Up) - TOM Series Part 2 (February 3, 2026) - [Your SOC's Dirty Secret: They Aren't Actively Hunting](https://www.focusedhunts.com/blog/articles/Your-SOCs-Dirty-Secret-Not-Hunting-Silent-Threats) - TOM Series Part 1 (January 20, 2026) - [High Tech Blind Spots: Validating the Modern Stack](https://www.focusedhunts.com/blog/articles/High-Tech-Blind-Spots-Validating-the-Modern-Stack) (January 22, 2026) - [The "Open Door" Illusion: Why Your Security Spend Might Be Failing You](https://www.focusedhunts.com/blog/articles/the-open-door-illusion) (January 15, 2026) - [2,721 Requests with Zero Valid Page Requests](https://www.focusedhunts.com/blog/articles/three-months-of-web-logs-revealed) (December 3, 2025) - [Mastering the Threat Hunting Hypothesis](https://www.focusedhunts.com/blog/articles/Threat-Hunting-Hypothesis-A-Guide-for-Risk-Leaders) (October 14, 2025) - [Redefining Cyber Success from Threat Hunting at the Paris Olympics](https://www.focusedhunts.com/blog/articles/Beyond-the-Podium-Redefining-Cyber-Success) (September 30, 2025) - [5 Signs Your Reactive Security Model is Failing](https://www.focusedhunts.com/blog/articles/Drowning-in-Alerts-Security-Model-Creating-More-Risk) (September 23, 2025) - [Why Monitoring isn't Enough](https://www.focusedhunts.com/blog/articles/Why-Monitoring-isnt-enough) (September 15, 2025) - [Threat Hunting is a Necessity, not a Luxury](https://www.focusedhunts.com/blog/articles/Why-Threat-Hunting-Is-a-Necessity-not-a-Luxury) (September 8, 2025) - [You Outsourced Monitoring but Who's Doing the Hunting?](https://www.focusedhunts.com/blog/articles/You-Outsourced-Monitoring-But-Who-is-Doing-the-Hunting) (September 1, 2025) - [Monitoring Alerts You. Hunting Assures You.](https://www.focusedhunts.com/blog/articles/Monitoring-Alerts-You.Hunting-Assures-You) (August 25, 2025) ## Hunting off the Red (Technical Intelligence Guides) Technical threat intelligence transformed into actionable hunting guidance. Each guide provides strategic briefings, operational context, and detection queries (KQL, Splunk). - [UNC6508 and the INFINITERED Backdoor Targeting Medical Research](https://www.focusedhunts.com/blog/hunting/INFINITERED-REDCap-Medical-Research-Backdoor) - Source: Google Threat Intelligence Group (July 1, 2026) - [STOCKSTAY: Detecting Turla's Multi-Component Espionage Backdoor](https://www.focusedhunts.com/blog/hunting/STOCKSTAY-Turla-Espionage-Backdoor) - Source: Google Threat Intelligence Group (July 1, 2026) - [Fox Tempest: AI-Themed Malvertising Delivers Signed Malware at Scale](https://www.focusedhunts.com/blog/hunting/Fox-Tempest-AI-Malvertising-Signed-Malware) - Source: Microsoft (June 8, 2026) - [UNK_DeadDrop: North Korean Phishing Turns VS Code Against Developers](https://www.focusedhunts.com/blog/hunting/UNK-DeadDrop-VSCode-Developer-Targeting) - Source: Proofpoint (June 8, 2026) - [PhantomRPC: Windows RPC Privilege Escalation via Server Impersonation](https://www.focusedhunts.com/blog/hunting/PhantomRPC-Windows-RPC-Privilege-Escalation) - Source: Focused Hunts (April 29, 2026) - [F5 BIG-IP CVE-2025-53521: BRICKSTORM Backdoor and Nation-State Exploitation](https://www.focusedhunts.com/blog/hunting/F5-BIG-IP-BRICKSTORM-Backdoor-Detection) - Source: Focused Hunts (March 30, 2026) - [GRIDTIDE: Detecting Google Sheets C2 in a Global Espionage Campaign](https://www.focusedhunts.com/blog/hunting/GRIDTIDE-Global-Espionage-Google-Sheets-C2) - Source: Focused Hunts (March 23, 2026) - [VEN0m Ransomware: BYOVD-Enabled File Encryption with AV/EDR Neutralization](https://www.focusedhunts.com/blog/hunting/VEN0m-Ransomware-BYOVD-Detection) - BYOVD ransomware detection guide (March 19, 2026) - [UAT-8837: China-Nexus APT Targeting North American Critical Infrastructure](https://www.focusedhunts.com/blog/hunting/UAT-8837-Critical-Infrastructure-APT) - China-nexus APT detection guide (March 14, 2026) - [Notepad++ Update Hijacking](https://www.focusedhunts.com/blog/hunting/Notepad-Plus-Plus-Update-Hijacking) - Supply chain compromise analysis (February 2, 2026) - [VoidLink: Detecting Advanced Cloud-Native Linux Malware](https://www.focusedhunts.com/blog/hunting/VoidLink-Cloud-Native-Malware) - Source: Check Point (January 13, 2026) - [Hunting Pro-Russia Hacktivists Targeting OT VNC](https://www.focusedhunts.com/blog/hunting/Hunting-Pro-Russia-Hacktivists-OT-VNC-Exploits) - Source: US CISA (December 10, 2025) - [APT24 Multi-Vector BADAUDIO Campaign Analysis](https://www.focusedhunts.com/blog/hunting/APT24-Multi-Vector-BADAUDIO-Campaign) - Source: Mandiant (December 8, 2025) - [Vibe Hacking: AI Data Extortion Techniques](https://www.focusedhunts.com/blog/hunting/Vibe-Hacking-AI-Data-Extortion) - AI-assisted intrusion detection (December 5, 2025) - [Detecting SSH Tor Backdoors in Military Networks](https://www.focusedhunts.com/blog/hunting/detecting-ssh-tor-backdoor-military-targeting) - Source: CISA (November 28, 2025) - [Qilin Ransomware Attack Chain Detection](https://www.focusedhunts.com/blog/hunting/qilin-ransomware-attack-chain-detection) - Full attack chain analysis (November 20, 2025) - [Talos Overview: Static Tundra Threat Analysis](https://www.focusedhunts.com/blog/hunting/talos-overview-static-tundra) - Source: Talos Intelligence (November 15, 2025) - [Hunting Microsoft Teams Threats - Detection Guide](https://www.focusedhunts.com/blog/hunting/Hunting-Microsoft-Teams-Threats-Detection-Guide) - Source: Microsoft Security (November 10, 2025) - [The Rise of Malware-Free Identity-Focused Intrusions](https://www.focusedhunts.com/blog/hunting/The-Rise-of-Malware-Free-Identity-Focused-Intrusions) - Source: CrowdStrike (November 5, 2025) - [Hunting EtherHiding: UNC5342 Analysis](https://www.focusedhunts.com/blog/hunting/Hunting-EtherHiding-UNC5342) - Source: Mandiant (October 28, 2025) - [Flax Typhoon ArcGIS Server Web Shell Compromise](https://www.focusedhunts.com/blog/hunting/Flax-Typhoon-ArcGIS-Server-Object-Extension-Web-Shell-Compromise) - Source: CISA/NSA (October 20, 2025) - [TrendMicro: Unmasking the Gentlemen Ransomware](https://www.focusedhunts.com/blog/hunting/TrendMicro-unmasking-the-gentlemen-ransomware) - Source: TrendMicro Research (October 12, 2025) - [Exposing the Espionage Tactics of China-Aligned TA415](https://www.focusedhunts.com/blog/hunting/Exposing-the-Espionage-Tactics-of-China-aligned-Threat-Actor-TA415) - Source: Proofpoint (October 5, 2025) - [Detecting Premier Pass as a Service APT Collaboration](https://www.focusedhunts.com/blog/hunting/Detecting-Premier-Pass-as-a-Service-APT-Collaboration) - Source: CISA (September 28, 2025) - [Analyzing Fake CAPTCHA Phishing Attacks](https://www.focusedhunts.com/blog/hunting/Analyzing-Fake-CAPTCHA-Phishing) - Credential harvesting detection (September 20, 2025) ## Contact - Website: https://www.focusedhunts.com - Contact page: https://www.focusedhunts.com/contact - LinkedIn: https://linkedin.com/company/focused-hunts