About

Matticus Hunt

Founder, Unknown². Principal consultant in adversary simulation and incident response. Came up on the defensive side — SOC teams, threat intelligence, detection engineering — then switched to offense.

Background

Defensive roots. Offensive practice.

Most red teamers come up through CTF competitions and academic exploitation research. My path was different. I spent years on the defensive side — building SOC teams, writing detection logic, running threat intelligence programs, and responding to real incidents under pressure.

That background shaped how I approach adversary simulation. When I'm operating against an environment, I know what the defenders are seeing — or not seeing. I know which log sources are typically gaps. I know what alert fatigue looks like at 2am, and I know which detections security teams trust versus which ones they've tuned to silence. That operational context makes the simulation more realistic and the findings more actionable.

I've been in the room for ransomware negotiations — with legal counsel, crisis communications teams, and decision-makers under breach disclosure pressure. I've briefed boards in the hours after an incident was confirmed. And I've built the detection engineering programs that the adversaries I now simulate are designed to evade.

Unknown² was founded on the premise that most organizations don't need more vulnerability findings. They need to know whether their security investment would actually stop a motivated adversary. That's the question we answer.

Areas of Expertise

Where the work lives.

Adversary Simulation

Full-scope red team operations replicating named threat actor behavior. MITRE ATT&CK-mapped technique execution with structured detection gap analysis.

Assumed Breach

Post-initial-access operations testing lateral movement detection, privilege escalation controls, and incident response time from an established foothold.

Incident Response

Emergency response and retainer-based IR support. Forensic investigation, containment strategy, and recovery planning under active incident conditions.

Ransomware Response

Negotiation alongside technical remediation. Offensive ransomware TTP knowledge applied directly to defensive response and recovery sequencing.

Detection Engineering

SIEM content development, log source architecture, and detection validation. Purple team engagements that produce detection logic, not just findings.

Executive Advisory

Board-level security briefings, fractional CISO support, and threat-to-business-risk translation for executives navigating high-stakes security decisions.

Speaking

Available for conference presentations and expert panels.

To discuss a speaking engagement, reach out directly at hello@unknown2.com.

Adversary Simulation at Scale

How to build and operate an adversary emulation program — from threat profiling and TTP selection through execution and detection gap closure. Practical methodology for organizations moving beyond generic penetration testing.

Red Team MITRE ATT&CK Detection Engineering

What Defenders Miss: An Operator's View

A frank account of the detection gaps and architectural assumptions that red teams reliably exploit — drawn from years of operating against defended environments. What security programs consistently fail to cover and why.

Blue Team SOC Threat Detection

Inside Ransomware Response

The operational reality of ransomware incidents — negotiation dynamics, technical investigation under breach pressure, recovery sequencing, and the decisions that determine outcome. For incident responders and security leaders.

Incident Response Ransomware Crisis Management

Translating Adversary Behavior for Boards

How to communicate threat actor capability and organizational risk to executive audiences without losing precision. For CISOs and security leaders navigating board-level conversations about cybersecurity investment.

Executive Advisory Risk Communication CISO

Get In Touch

Engagements, speaking, and advisory work.

Whether you're evaluating a red team engagement, managing an active incident, looking for a speaker, or need fractional CISO support — the best first step is a direct conversation.

Start a Conversation →