Imposter to Hunter: My First Year as a Threat Hunter

Allyn Roberts (Threat Hunt Analyst · Intermountain Health)

SAINTCON 2025 · Day 1 · Main Track 3

Overview

In "Imposter to Hunter: My First Year as a Threat Hunter," Allyn Roberts, a Threat Hunt Analyst at Intermountain Health, shares his deeply personal and highly relatable journey from feeling like an imposter in the cybersecurity field to confidently embracing his role as a threat hunter. The talk chronicles Roberts' progression through various non-technical cyber roles, his persistent struggle with imposter syndrome, and the pivotal moments and resources that ultimately enabled him to transition into a highly technical threat hunting position.

Watch on YouTube

Visual summary for Imposter to Hunter: My First Year as a Threat Hunter by Allyn Roberts
Visual summary for Imposter to Hunter: My First Year as a Threat Hunter by Allyn Roberts

Key moments

  1. 0:00 Overcoming imposter syndrome after first cloud hunt
  2. 1:45 Presentation's goal: overcoming imposter syndrome in cyber
  3. 2:09 Early imposter syndrome in college and first internship
  4. 3:58 Eight years in non-technical roles, building technical passion
  5. 6:18 Defcon talk sparks interest in cyber threat intelligence
  6. 7:20 Job requirements lead to discouragement and seeking advice
  7. 8:09 Shadowing threat team, discovering passion for hunting

Imposter to Hunter: My First Year as a Threat Hunter

Speakers: Allyn Roberts, Threat Hunt Analyst, Intermountain Health

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=Qxi_yOiI0cw

Overview

In "Imposter to Hunter: My First Year as a Threat Hunter," Allyn Roberts, a Threat Hunt Analyst at Intermountain Health, shares his deeply personal and highly relatable journey from feeling like an imposter in the cybersecurity field to confidently embracing his role as a threat hunter. The talk chronicles Roberts' progression through various non-technical cyber roles, his persistent struggle with imposter syndrome, and the pivotal moments and resources that ultimately enabled him to transition into a highly technical threat hunting position.

This presentation is more than just a career retrospective; it serves as an inspiring guide for anyone aspiring to enter or advance within technical cybersecurity roles, particularly those grappling with self-doubt. Roberts provides practical advice, highlights crucial frameworks like the Pyramid of Pain and the PEAK Framework, and emphasizes the importance of continuous learning, proactive engagement, and strategic networking. His narrative underscores that a successful career in cybersecurity is often built not on a single breakthrough, but on a cumulative series of small, consistent efforts and a willingness to push past discomfort.

Background

▶ Watch: Overcoming imposter syndrome after first cloud hunt (0:00)

Allyn Roberts' journey into threat hunting was neither linear nor immediate. His academic path began with a seven-year bachelor's degree, during which he switched majors three times, from mechanical engineering to computer science, finally graduating in Management Information Systems (MIS). This early academic experience was Roberts' first encounter with imposter syndrome, particularly in a digital circuits lab and while struggling with programming concepts. Despite these initial hurdles, an internship at Intermountain Health's Security Operation Center (SOC) marked his entry into cybersecurity. However, this early role reinforced his self-doubt, as he felt hired primarily for availability rather than skill.

For the subsequent eight years, Roberts held various non-technical cybersecurity roles at Intermountain Health. He worked on the disaster recovery team, assisting other teams in creating recovery plans, and later joined the "Office of the CISO," where he managed cyber contracts and contributed to an apprenticeship program. While these roles were enjoyable and provided valuable organizational experience, they were not technically intensive, perpetuating his feeling of being an imposter, especially when surrounded by seasoned professionals.

A turning point arrived around 2021 when Roberts attended a Defcon presentation on cyber threat intelligence (CTI). This sparked a keen interest, leading him to seek out online resources and follow CTI professionals, including Andy Piazza, whose CTI guide proved instrumental. Yet, job postings for even entry-level CTI roles often required two or more years of technical experience, again triggering his imposter syndrome and making him feel stuck.

In a proactive move, Roberts reached out to Andy Piazza for advice. Piazza's recommendation—to "shadow a team"—became a catalyst for change. Roberts secured approval from his manager to shadow a newly formed threat team, where he observed a colleague focused on threat hunting. Witnessing the practical application of tools, query construction, and investigation techniques ignited a strong desire to pursue threat hunting himself. This shadowing period, combined with significant departmental changes, eventually led to his opportunity to join the threat team, marking the beginning of his challenging but ultimately rewarding first year as a threat hunter. The initial months were overwhelming, characterized by a steep learning curve for numerous tools and data types, reinforcing his persistent imposter syndrome, but he persevered, driven by an inherent enjoyment of the hands-on aspects of cyber security he had cultivated as a hobby.

Key Findings

▶ Watch: Early imposter syndrome in college and first internship (2:09)

Roberts' first year as a threat hunter yielded several key findings, both personal and technical, that shaped his understanding of the role and his place within it. Foremost among these was the realization that imposter syndrome is a pervasive experience, even for those actively engaged in the field. He openly shared his struggles with self-doubt, not just when starting out, but even when preparing for his SAINTCON presentation. The critical insight here is that persistence and a focus on personal growth, rather than comparison to others, are vital for overcoming it.

Technically, Roberts discovered the immense value of structured frameworks in transforming aimless investigations into effective threat hunts. He highlighted two such frameworks:

  1. The Pyramid of Pain: This concept illustrates the increasing difficulty for threat actors to change indicators of compromise (IOCs) as defenders move up the pyramid. Roberts learned that focusing on tactics, techniques, and procedures (TTPs), rather than easily mutable hash values or IP addresses, makes an adversary's life significantly harder. This shift in perspective was crucial for making his threat hunts more impactful.
  2. The PEAK Framework: Standing for Prepare, Execute, Act, and Knowledge Repository, this framework provided Roberts with a systematic approach to threat hunting. It helped him move beyond ad-hoc querying to a more organized process that involved thorough preparation, structured execution, decisive action based on findings, and the invaluable step of documenting knowledge for future hunts. This framework brought much-needed order to his previously "aimless" hunting efforts.

Another significant finding was the cumulative nature of skill development. Roberts initially dismissed his past experiences—college programming, SOC internship, non-technical roles, home lab experiments with Linux and containers—as irrelevant. However, he later realized that these seemingly disparate experiences provided a foundational understanding that proved incredibly useful in his threat hunting role, whether in reading code, writing scripts, or understanding system architectures. This underscored that there isn't a single "pivotal moment" that transforms one into a threat hunter; rather, it's a continuous aggregation of learning and doing over time.

Finally, Roberts emphasized the importance of proactive engagement and focused learning. He shared his early tendency to "topic-hop" without gaining deep understanding, contrasting it with the effectiveness of concentrating on specific areas. His advice to "be proactive" extends to seeking out resources, participating in hands-on activities like CTFs, and engaging in meaningful networking, exemplified by his outreach to Andy Piazza and his observations on effective vs. superficial networking efforts.

Technical Deep Dive

▶ Watch: Eight years in non-technical roles, building technical passion (3:58)

Roberts' journey into threat hunting was significantly aided by the adoption of established frameworks and the development of core technical competencies. His shift from high-level cybersecurity understanding to the deep technical insights required for threat hunting was supported by two primary conceptual models: the Pyramid of Pain and the PEAK Framework.

The Pyramid of Pain, originally conceived by David Bianco, provides a hierarchical model for classifying indicators of compromise (IOCs) and understanding their impact on adversaries. Roberts explained how this framework fundamentally changed his approach to threat hunting. At the base of the pyramid are hash values (e.g., MD5, SHA256) and IP addresses. These are the easiest for threat actors to change; blocking or alerting on them offers minimal pain to an attacker, who can simply pivot to new infrastructure or repackage malware. Moving up, the pyramid includes domain names, which are slightly more costly for an attacker to replace, followed by network artifacts (e.g., C2 beacon patterns, specific HTTP headers) and host artifacts (e.g., registry keys, file paths, mutexes). While these require more effort to alter, they are still relatively manageable for a determined adversary.

The most impactful level, and the focus for effective threat hunting, is Tactics, Techniques, and Procedures (TTPs). TTPs describe how an adversary operates—their methods for initial access, privilege escalation, lateral movement, persistence, and exfiltration. Examples include using specific PowerShell commands for reconnaissance, exploiting a particular vulnerability (like CVE-2023-XXXX if applicable, though not mentioned in this talk), or employing a unique sequence of actions to achieve an objective. Roberts highlighted that TTPs are the most painful for threat actors to change because they represent their operational tradecraft, requiring significant time, resources, and often retooling to develop new ones. By hunting for and blocking TTPs, defenders can disrupt an attacker's entire operational methodology, forcing them back to the drawing board and significantly increasing the cost of their attack. This shift in focus from low-fidelity IOCs to high-fidelity TTPs was a critical component of Roberts' growth as a threat hunter.

Complementing the Pyramid of Pain, the PEAK Framework provided Roberts with a structured methodology for conducting threat hunts. Prior to adopting PEAK, he described his hunts as "aimless," often jumping directly into querying logs without clear objectives. The PEAK Framework, standing for:

  • Prepare: This phase involves defining the scope of the hunt, formulating hypotheses (e.g., "Are adversaries using X technique in our environment?"), identifying relevant data sources, and understanding the normal baseline behavior of systems. Roberts emphasized that this preparation prevents wasted effort and ensures hunts are targeted.
  • Execute: This is where the actual data collection and analysis occur. It involves crafting and running queries against various log sources (e.g., endpoint detection and response (EDR) logs, network logs, cloud logs). Roberts specifically mentioned learning Kusto Query Language (KQL), a powerful query language used in Microsoft Sentinel and Azure Data Explorer, through resources like KC7 Cyber. KQL allows for complex data filtering, aggregation, and analysis, essential for sifting through large volumes of security data.
  • Act: Based on the findings during execution, this phase involves taking concrete steps. This could include creating new detections, implementing blocks, patching vulnerabilities, isolating compromised systems, or initiating a full incident response. Roberts' experience presenting recommendations from his first cloud hunt to seasoned cloud teams exemplifies this "Act" phase.
  • Knowledge Repository: The final, crucial step is documenting the hunt's process, findings, and any new intelligence gained. This repository serves as a valuable resource for future hunts, helps refine hypotheses, improves detection capabilities, and contributes to the overall organizational security posture. It ensures that lessons learned are not lost and contribute to continuous improvement.

Beyond these frameworks, Roberts also touched upon the practical technical skills that unexpectedly proved valuable. His early exposure to Linux command line operations and learning to build containers during his home lab experiments—initially perceived as hobbies—later became directly applicable in his threat hunting role, aiding in scripting, understanding system configurations, and analyzing artifacts. This highlights that a broad, hands-on technical foundation, even if gained outside formal job requirements, significantly enhances a threat hunter's capabilities.

Demo / Proof of Concept

▶ Watch: Job requirements lead to discouragement and seeking advice (7:20)

While Allyn Roberts' talk did not feature a live technical demonstration or a specific proof of concept in the traditional sense, he powerfully demonstrated the outcome and value of applying structured threat hunting methodologies. The most significant "demonstration" he provided was the account of his first successful cloud threat hunt. Having only been hunting in the cloud environment for a matter of weeks, he was tasked with presenting his team's findings and recommendations to experienced cloud teams who had managed the environment for years.

This experience, initially fraught with intense imposter syndrome, culminated in his recommendations being "well-received." The cloud teams acknowledged the quality of their work and its contribution to making the cloud environment "more secure." This real-world validation served as a powerful proof of concept for the effectiveness of his newly adopted structured approach, particularly the PEAK Framework, in identifying actionable security improvements.

Furthermore, Roberts highlighted KC7 Cyber as a free, hands-on program that effectively functions as a learning environment for practical security skills. KC7 Cyber offers modules designed to teach users how to write queries in KQL, conduct incident investigations, analyze logs, and identify evidence of attacks. While not a personal demo, his strong endorsement of this resource indicates its utility in providing a simulated, practical experience for aspiring threat hunters to develop the skills necessary for real-world scenarios. This program effectively serves as a "proof of concept" for skill acquisition in a practical, query-based investigation context.

Defensive Implications

▶ Watch: Shadowing threat team, discovering passion for hunting (8:09)

Allyn Roberts' journey offers profound implications for both individual security professionals and organizations seeking to build robust defensive capabilities, particularly in the realm of threat hunting.

For individual defenders, Roberts' experience underscores the universality of imposter syndrome and provides a roadmap for overcoming it. The key is proactive, focused learning and continuous engagement. This means not just attending conferences, but actively participating in CTFs and hands-on challenges. It involves dedicating time to personal development, whether through reading cybersecurity books, setting up home labs to learn foundational skills like the Linux command line and containerization, or pursuing advanced education like graduate school. Crucially, Roberts advises against "topic-hopping," instead advocating for a deep dive into specific subjects to build genuine expertise. His story also highlights the power of meaningful networking, emphasizing genuine connection and information exchange over simply accumulating contacts. Documentation, as he points out, is not merely administrative but a critical skill that enhances writing abilities essential for threat reports and broader cybersecurity communication.

For organizations, Roberts' narrative provides actionable insights into fostering talent and strengthening security posture:

  1. Invest in Internal Growth and Mentorship: Roberts' critical turning point came from shadowing an experienced threat hunter. Organizations should formalize or encourage such mentorship and shadowing programs, recognizing that internal talent development can be more effective than solely relying on external hires, especially for specialized roles like threat hunting.
  2. Embrace Diverse Backgrounds: Roberts' path from non-technical roles to threat hunting demonstrates that valuable cybersecurity professionals can emerge from various backgrounds. Organizations should look beyond traditional technical degrees and consider individuals with strong analytical skills, problem-solving abilities, and a proven desire to learn.
  3. Support Continuous Learning: Providing access to conferences, training, and educational resources is vital. Roberts' personal investment in learning outside work suggests that when organizations support this drive, it yields highly motivated and skilled employees.
  4. Adopt Structured Methodologies: The successful application of the Pyramid of Pain and the PEAK Framework transformed Roberts' aimless hunts into impactful ones. Security teams should integrate such structured frameworks into their threat hunting programs to ensure efficiency, effectiveness, and consistent results. Prioritizing the hunting of TTPs over easily mutable IOCs will significantly increase the pain for adversaries.
  5. Leverage Free and Accessible Resources: Roberts' endorsement of KC7 Cyber as a free platform for learning KQL and incident investigation highlights that effective skill development doesn't always require expensive tools or training. Organizations can recommend or integrate such resources into their training curricula for junior analysts.
  6. Foster a Culture of Contribution: The positive reception of Roberts' recommendations by senior cloud teams, despite his relative inexperience in that specific environment, demonstrates the importance of a culture where junior team members feel empowered to share findings. This encourages innovation and ensures that valuable insights from all levels are considered.
  7. Emphasize Proactivity and Persistence: Roberts' story is a testament to the power of pushing through discouragement. Organizations can cultivate this by celebrating small wins, providing constructive feedback, and recognizing the effort involved in skill acquisition, especially in challenging fields like threat hunting.

Ultimately, Roberts' talk provides a compelling argument for building a threat hunting capability that is not only technically proficient but also nurtured through a supportive environment that values continuous learning, structured processes, and the growth of its people.

Key Takeaways

  • Imposter syndrome is a common experience, not a barrier: Many professionals, even experienced ones, grapple with self-doubt. Persistent effort and focusing on personal growth rather than comparing oneself to others are key to overcoming it.
  • Foundational skills are cumulative and invaluable: Seemingly unrelated past experiences, such as college programming, understanding the Linux command line, or building containers, often provide essential building blocks for advanced technical roles like threat hunting.
  • Structured frameworks are critical for effective threat hunting: Adopting models like the Pyramid of Pain (shifting focus to TTPs) and the PEAK Framework (Prepare, Execute, Act, Knowledge Repository) transforms aimless searching into targeted, impactful security operations.
  • Proactive engagement and focused learning accelerate growth: Actively seeking out hands-on experiences (CTFs, home labs), dedicating time to deep dives into specific topics, and continuously learning new tools (e.g., KQL through KC7 Cyber) are essential for skill development.
  • Meaningful networking and documentation are crucial for career progression: Engaging with peers and mentors for genuine knowledge exchange, and consistently documenting findings and processes, significantly enhance professional growth and communication skills.
  • Help others, regardless of your experience level: Sharing knowledge, even if you're only a little further along in your journey, can significantly benefit those just starting out and reinforce your own understanding.

About the Speaker(s)

Allyn Roberts is a Threat Hunt Analyst at Intermountain Health, where he has dedicated 10 years of his career to cybersecurity. His academic background is in Management Information Systems, which provided a foundation for his entry into the field. Roberts' professional journey at Intermountain Health began with an internship in the Security Operation Center, followed by approximately eight years in various non-technical roles, including disaster recovery and positions within the Office of the CISO, where he managed cyber contracts and contributed to an apprenticeship program. Driven by a burgeoning interest in hands-on cybersecurity, he pursued personal learning through conferences, CTFs, home lab experiments (including Linux and containerization), and graduate studies in cybersecurity. His passion for threat intelligence, sparked at Defcon, eventually led him to shadow and then join Intermountain Health's threat team. Roberts is a testament to continuous learning, perseverance in the face of imposter syndrome, and the power of structured methodologies in developing a successful career in technical cybersecurity roles. He actively shares resources and encourages others on their cybersecurity journeys, maintaining a website with helpful materials.

All talks from SAINTCON 2025