<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>ThreatHunting - Tag - St0pp3r's Blog</title><link>https://st0pp3r.blog/tags/threathunting/</link><description>ThreatHunting - Tag - St0pp3r's Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://st0pp3r.blog/tags/threathunting/" rel="self" type="application/rss+xml"/><item><title>Threat Hunting Using Pair Probabilities</title><link>https://st0pp3r.blog/threat-hunting-using-pair-probabilities/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0800</pubDate><author><name>st0pp3r</name></author><guid>https://st0pp3r.blog/threat-hunting-using-pair-probabilities/</guid><description><![CDATA[<div class="featured-image">
                <img src="/images/threat-hunting-using-pair-probabilities/thumbnail.png" referrerpolicy="no-referrer">
            </div>Upon digging around Microsoft&rsquo;s documentation for user-defined functions I stumbled on the function pair_probabilities_fl(). This function calculates probabilities and some additional metrics for a pair of categorical variables, A and B. In this blog post, we are exploring the possibility of using the pair probabilities function for threat hunting.
The documentation explains the output metrics in detail, but I am going to briefly go through the key points to help provide some context for the rest of the blog.]]></description></item></channel></rss>