Hunting is proactive searching for threats that may go unidentified by intrusion detection, log alerting, or antivirus software. Hunting allows organizations to find unknown threats while gaining a deeper understanding of their networks. This presentation will show how to hunt through network data at each stage of the kill chain. Three kinds of hunts will be presented: stacking, tracking, visualization. Working implementations used by Cisco Active Threat Analytics team will be presented for finding attacks pre-exploitation, exploitation attempts, and post-exploitation.