How can threat intelligence and detection teams build a collaborative, productive relationship and improve overall organizational security? Our talk will focus on how detection engineering and threat hunting (DEaTH) informs detection pipelines to enable automated forensic analysis of the biggest threats to enterprises, and how security practitioners can use this type of data to improve their own defence. Each day Proofpoint analyses billions of emails, and millions of those are identified as malicious. We will discuss how to work together with cross-functional teams to identify new techniques and create detections to prevent threat actor exploitation at scale, while automating configuration and forensic extraction, and MITRE ATT&CK mapping for end-users. This talk will provide an in-depth look into the CTI and detection lifecycle and the symbiotic relationship between threat hunting and detection engineering and how researchers and organizations can leverage it in their own defence processes. We will demonstrate multiple case studies from both cybercrime and APT threat actors. Each example will provide examples of challenges in automated detection and forensic extraction and highlight the tactics, techniques, and procedures (TTPs) used in each campaign that have been observed across the threat landscape.