Knowledge / detection IR threat-intel

Threat hunting

Assume they are already in. Ask a question of your logs. Not a dashboard tour.

Threat hunting is structured search for activity you do not already alert on, driven by a hypothesis: a TTP, a new technique, a gap. SIEM and EDR are the library. The hunt is the question.

Write the hypothesis, the data you need, the finding, and whether it becomes a detection. Random keyword grepping is not a program. Feed results into detections, and into the IR playbook when you actually find something.

See also: Tactics, techniques, and procedures, SIEM, Threat intelligence, IR playbook, Security operations centre.