This session will dive deep into how Passive DNS (pDNS) can be leveraged as a core tool for advanced threat hunting and detecting sophisticated adversary behavior across the attack lifecycle. Introduction to Passive DNS: A brief overview of how pDNS data is collected, stored, and queried, and why it's essential for threat hunting. Building Data-Driven Hypotheses: Attendees will learn how to move from the "null hypothesis" (no evidence of compromise) to generating meaningful, alternative hypotheses based on DNS traffic patterns and behaviors. Identifying Threat Actor Infrastructure: We will demonstrate techniques to trace attacker infrastructure using historical DNS records, including domain generation algorithms (DGAs) and fast-flux networks. Augmenting Threat Hunting with pDNS: The session will cover how to integrate pDNS into existing security workflows to detect and prevent threats in real-time and at scale. This session will introduce an analytical framework grounded in hypothesis-driven investigation—bridging the gap between data science and threat intelligence. Unlike conventional approaches to DNS analysis, which often rely on signatures or blacklists, this method empowers threat hunters to actively hypothesize and prove/disprove theories using real-world DNS data, increasing the likelihood of uncovering zero-day and sophisticated threats.