Cyber Threat Hunting

Threat hunting (also known as cyber threat hunting) lies at the heart of modern security response services. It seeks unknowns in a security environment. It goes beyond security information and event management (SIEM) and other passive detection methods. Instead, threat hunting uses proactive search methods through networks, endpoints, and datasets to hunt suspicious activities that evade the detection of existing tools.

Two Types of Threat Hunting 

Structured hunting looks for the indications of attack (IoA) and an attacker’s techniques tactics, and procedures (TTPs). All structured hunts use and align to attacker TTPs. This is how threat hunters often identify threat actors before they can cause damage to a security environment. This type of hunt uses the MITRE Adversary Tactics Techniques and Common Knowledge (ATT&CK) framework, which uses enterprise and PRE-ATT&CK frameworks.

Unstructured hunting begins with a trigger event. This approach is better suited to intelligence-based hunting, where the trigger could be an indicator of compromise.

Often, the trigger is the cue for a hunter to start looking for pre- and post-detection patterns. Hunters can look for these patterns in old data records wherever data retention and associated offenses permit. The hunter’s approach is based on this research.

Hunting Models 

Threat hunting uses three models, which include:

  • Intel-based hunting. This reactive hunting model uses the IoCs from threat intelligence sources as inputs. Then, the hunt uses pre-designed rules set up by threat intelligence and the SIEM.
  • Hypothesis hunting with a threat hunting library. This proactive hunting model is well-suited to the MITRE ATT&CK approach. It uses globally recognized detection methods to identify malware attacks and advanced, persistent attackers. Hypothesis-based hunts use attacker TTPs and IoAs. Hunters identify bad actors based on domain, environment, and attack behavior data. Used together, hunters create a hypothesis that aligns with the MITRE framework.

After identifying a behavior, threat hunters monitor activities for patterns that help to detect, identify, and isolate the threat before it does damage.

  • Custom hunting. This approach uses industry-specific hunting methods and AI situational awareness. Custom hunting methods identify anomalies in EDR tools and the SIEM, and customer requirements provide the data. You can run these hunts proactively with requirements received from customers or with situation-based information, such as targeted attacks and geopolitical issues.

Hunting Frameworks 

Here are two of the most popular threat hunting frameworks:

  • Targeted hunting methods integrated with threat intelligence. This framework aligns with intel-based hunting methods. Triggers come from threat intelligence, historical incidents, red teaming activities, and other sources.
  • MITRE PRE-ATT&CK and ATT&CK. This framework includes common methods used by adversaries and extensive knowledge bases that you can apply to specific threat models.

By combining these methods and resources, threat hunting teams get the solid foundation that they need to stand against cyber attackers.

Glossary Term

Disaster Recovery Plan

What is a Disaster Recovery Plan? A disaster recovery plan (DRP) is an essential document for any ...
Read More
Glossary Term

Web Application Security

What is Web Application Security? Web Application Security is the process of securing web applications and websites ...
Read More
Uncategorized

Vishing

What is Vishing? Voice phishing or vishing is a form of phishing attack where an attacker would ...
Read More
Glossary Term

vCISO

What is a vCISO? A vCISO is a Virtual Chief Information Security Officer. A traditional CISO is ...
Read More
Glossary Term

vCIO

What is a Virtual Ciso? A vCIO is a Virtual Chief Information Officer. The vCIO is someone ...
Read More
Glossary Term

Security Operations Center

What is a Security Operations Center? A Security Operations Center, commonly referred to as a SOC, is ...
Read More
Glossary Term

SMB

What is an SMB  SMB stands for small and medium-sized businesses. How Should SMBs Approach Their IT ...
Read More
Glossary Term

Security Information and Event Management (SIEM)

What is SIEM? Security Information and Event Management (SIEM) is a tool that organizations can use to ...
Read More
Glossary Term

SharePoint Security

What is SharePoint? SharePoint is a web-based collaboration application developed by Microsoft that is being used by ...
Read More
Glossary Term

Recovery Point Objective (RPO) and Recovery Tip Objective (RTO)

What is RPO? Recovery Point Objective (sometimes referred to as RPO or simply recovery point) is a ...
Read More
Glossary Term

Ransomware Detection & Account Recovery

What is Ransomware Detection Ransomware is malicious software that takes control of and encrypts private data for ...
Read More
Glossary Term

Phishing (Vishing)

Phishing is a practice where an attacker attempts to gain access to a private network by sending ...
Read More
Glossary Term

Network Operations Center – NOC Meaning

A network operations center — commonly known as a NOC — is a facility staffed by IT ...
Read More
Glossary Term

Network Traffic Analyzer & Network Traffic Analysis Tools

What is A Network Traffic Analyzer A network security analyzer is a network security tool that provides ...
Read More
Glossary Term

Network Security Threats & Network Security Attacks

What are Network Security Attacks Network Security Attacks are unauthorized actions taken against digital assets within a ...
Read More
Glossary Term

Network Security & Network Security Tools

What is Network Security To define network security, it is important to understand what is meant by ...
Read More
Glossary Term

Multi-Factor Authentication (MFA)

What is Multi-Factor Authentication Multi-factor authentication is the process by which a user verifies their identity to ...
Read More
Glossary Term

Microsoft Security

What is Microsoft Security and Why is it Important? Microsoft security is an important part of the ...
Read More
Glossary Term

Malware Detection

What is Malware Detection Malware detection is important in today’s cybersecurity as malware is software that is ...
Read More
Glossary Term

Intrusion Detection and Prevention Systems

What is an Intrusion Detection System (IDS) An intrusion detection system (IDS) is a device or software ...
Read More
Glossary Term

End User Security Awareness Training

What is End-User Training End-user training is an important aspect of cyber hygiene and successful system implementation ...
Read More
Glossary Term

Department of Defense & DoD Contractors

What is The Primary Responsibility of the Department of Defense? The Department of Defense (DoD) is the ...
Read More
Glossary Term

Cybersecurity Threats

What Are Cybersecurity Threats When a business closes for the day the doors are locked and the ...
Read More
Glossary Term

Cyber Security Incident Response (CIRT)

What is Incident Response in Cyber Security An incident response plan is a document that outlines an ...
Read More
Glossary Term

Cloud Security Solutions

What are Cloud Security Solutions? Cloud-based security is the umbrella term used to describe the resources and ...
Read More
Glossary Term

Business Continuity Plan

What is a Business Continuity Plan?  A business continuity plan — not to be mistaken with a ...
Read More
Glossary Term

Cyber Threat Hunting

Threat hunting (also known as cyber threat hunting) lies at the heart of modern security response services. ...
Read More
Glossary Term

Artificial Intelligence (AI) Security

Cybersecurity is one of many areas in which artificial intelligence (AI) provides a wide range of benefits. ...
Read More

Glossary Term

Disaster Recovery Plan

What is a Disaster Recovery Plan? A disaster recovery plan (DRP) is an essential document for any ...
Read More
Glossary Term

Web Application Security

What is Web Application Security? Web Application Security is the process of securing web applications and websites ...
Read More
Uncategorized

Vishing

What is Vishing? Voice phishing or vishing is a form of phishing attack where an attacker would ...
Read More
Glossary Term

vCISO

What is a vCISO? A vCISO is a Virtual Chief Information Security Officer. A traditional CISO is ...
Read More
Glossary Term

vCIO

What is a Virtual Ciso? A vCIO is a Virtual Chief Information Officer. The vCIO is someone ...
Read More
Glossary Term

Security Operations Center

What is a Security Operations Center? A Security Operations Center, commonly referred to as a SOC, is ...
Read More
Glossary Term

SMB

What is an SMB  SMB stands for small and medium-sized businesses. How Should SMBs Approach Their IT ...
Read More
Glossary Term

Security Information and Event Management (SIEM)

What is SIEM? Security Information and Event Management (SIEM) is a tool that organizations can use to ...
Read More
Glossary Term

SharePoint Security

What is SharePoint? SharePoint is a web-based collaboration application developed by Microsoft that is being used by ...
Read More
Glossary Term

Recovery Point Objective (RPO) and Recovery Tip Objective (RTO)

What is RPO? Recovery Point Objective (sometimes referred to as RPO or simply recovery point) is a ...
Read More
Glossary Term

Ransomware Detection & Account Recovery

What is Ransomware Detection Ransomware is malicious software that takes control of and encrypts private data for ...
Read More
Glossary Term

Phishing (Vishing)

Phishing is a practice where an attacker attempts to gain access to a private network by sending ...
Read More
Glossary Term

Network Operations Center – NOC Meaning

A network operations center — commonly known as a NOC — is a facility staffed by IT ...
Read More
Glossary Term

Network Traffic Analyzer & Network Traffic Analysis Tools

What is A Network Traffic Analyzer A network security analyzer is a network security tool that provides ...
Read More
Glossary Term

Network Security Threats & Network Security Attacks

What are Network Security Attacks Network Security Attacks are unauthorized actions taken against digital assets within a ...
Read More
Glossary Term

Network Security & Network Security Tools

What is Network Security To define network security, it is important to understand what is meant by ...
Read More
Glossary Term

Multi-Factor Authentication (MFA)

What is Multi-Factor Authentication Multi-factor authentication is the process by which a user verifies their identity to ...
Read More
Glossary Term

Microsoft Security

What is Microsoft Security and Why is it Important? Microsoft security is an important part of the ...
Read More
Glossary Term

Malware Detection

What is Malware Detection Malware detection is important in today’s cybersecurity as malware is software that is ...
Read More
Glossary Term

Intrusion Detection and Prevention Systems

What is an Intrusion Detection System (IDS) An intrusion detection system (IDS) is a device or software ...
Read More
Glossary Term

End User Security Awareness Training

What is End-User Training End-user training is an important aspect of cyber hygiene and successful system implementation ...
Read More
Glossary Term

Department of Defense & DoD Contractors

What is The Primary Responsibility of the Department of Defense? The Department of Defense (DoD) is the ...
Read More
Glossary Term

Cybersecurity Threats

What Are Cybersecurity Threats When a business closes for the day the doors are locked and the ...
Read More
Glossary Term

Cyber Security Incident Response (CIRT)

What is Incident Response in Cyber Security An incident response plan is a document that outlines an ...
Read More
Glossary Term

Cloud Security Solutions

What are Cloud Security Solutions? Cloud-based security is the umbrella term used to describe the resources and ...
Read More
Glossary Term

Business Continuity Plan

What is a Business Continuity Plan?  A business continuity plan — not to be mistaken with a ...
Read More
Glossary Term

Cyber Threat Hunting

Threat hunting (also known as cyber threat hunting) lies at the heart of modern security response services. ...
Read More
Glossary Term

Artificial Intelligence (AI) Security

Cybersecurity is one of many areas in which artificial intelligence (AI) provides a wide range of benefits. ...
Read More