Hack.lu 2026

Peter Manev

Member of the executive team at Open Network Security Foundation (OISF) and Suricata Project Evangelist. I have over 20 years of experience in the IT Security industry, including enterprise-level practice. Passionate user, developer, and explorer of innovative open-source security software. I have been involved with Suricata IDS/IPS/NSM from its very early days in 2009 as QA and training lead.

Co-founder and chief strategy officer (CSO) of Stamus Networks, a company providing commercial and open-source network detection and response solutions based on Suricata.

One of the lead maintainers of ClearNDR Community (former SELKS), the popular turnkey open-source based implementation of Suricata IDS/IPS/NSM.

Co-author of The Security Analyst’s Guide to Suricata book written with Eric
Leblond. SEPTun I and SEPTun II Suricata Extreme Performance Tuning series.

Peter is a writer, content creator and open source contributor about Network Cyber Security and authored over 150 blogs , 500 threat hunting visualizations and dashboards for Kibana/Elasticsearch and OpenSearch , written over 2000 detection rules, developed over 150 threat hunting trigger routines.

Authored scientific papers on Cyber Security Strategy and Defense.

Peter has developed and delivered over 100 hands on Cyber Security trainings and workshops for different government, public, private and defense organizations in US and Europe like the US Space command, US Missile command, NATO units.

10 years of hands on experience and instructor for NATO Counter Cyber Operations and Offensive Cyber Operations units in some of the largest live-fire cyber exercises such as Crossed Swords, Locked Shields.

Peter often engages in private or public training, workshops and speaking events in the area of cyber security and threat hunting at conferences such as DeepSec, FOSDEM, Troopers, BotConf, BSides, DefCon, Suricon, HackLu, SharkFest, RSA, Flocon, MIT Lincoln Lab and others.


Session

10-21
14:15
120min
HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata
Peter Manev, Eric Leblond

HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata

This workshop introduces HHAMMERR, a specialized threat hunting framework designed for modern detection engineering: Hypothesis, Hunt, Analyze, Modulate, Manage, Enhance, Refine, and Repeat. Built on the philosophy of "hunt manually once, automate forever," the session demonstrates how to move beyond traditional query-based methods into cost-effective, high-accuracy AI integration.

Using Suricata—the industry-standard open-source network analysis engine—as the primary data source, attendees will explore how to leverage its rich protocol, flow, and anomaly logs for deep network visibility. The workshop bridges the gap between traditional SIEM-based hunting and Agentic AI, focusing on building precise "AI Skills" rather than simply processing massive datasets.

Key Takeaways:

  • Methodology: Implementation of the HHAMMERR cycle to standardize hunting workflows.
  • Optimization: Techniques for building Agentic AI tools that prioritize data sovereignty, performance, and low token costs.
  • Practical Application: Hands-on malware hunt scenarios designed to provide immediate, actionable value for blue teams.

Moving past the hype of generative AI, this session provides a pragmatic roadmap for defenders to illuminate perimeter blind spots and automate complex detection tasks using the Claude AI plugin ecosystem and Suricata's network security data.

topic: hack.lu
Hollenfels