Threat hunting
Assume they are already in. Ask a question of your logs. Not a dashboard tour.
Threat hunting is structured search for activity you do not already alert on, driven by a hypothesis: a TTP, a new technique, a gap. SIEM and EDR are the library. The hunt is the question.
Write the hypothesis, the data you need, the finding, and whether it becomes a detection. Random keyword grepping is not a program. Feed results into detections, and into the IR playbook when you actually find something.
See also: Tactics, techniques, and procedures, SIEM, Threat intelligence, IR playbook, Security operations centre.
