Threat Hunting Overview
-
1.1
What is Threat Hunting?
- Proactively looking for threats in infrastructure using logs from endpoints, network devices, authentication systems, etc.
- Proactive vs reactive:
- Reactive — alerts from EDR, SOC, SIEM, IPS, etc.
- Proactive — searching through logs for indicators of compromise.
- Reactive methods are insufficient for advanced threats.
- Uses "assumption of breach."
- Does not replace alert-based detections — it's part of defense-in-depth.
-
1.2
Assume Breach
- Investigating and analyzing while assuming a threat actor is on the network.
- Requires many other assumptions and hypotheses:
- System that may be compromised
- How the system may be compromised
- Threat actor involved (adversary TTPs)
- Not necessarily reacting to any threat or alert.
-
1.3
Threat Hunting vs. Incident Response
- Threat hunting ≠ incident response.
- TH is a passive activity.
- IR is an active activity.
- Threat hunters and incident responders work closely together:
- Hunters discover threats and relay information to responders.
- Responders often gather additional information to provide to hunters — hash values, memory dumps, disk images, file contents, etc. — plus additional indicators for new threat hunts.
- Responding to threats alters data on systems — could affect an in-progress hunt.
Where TH fits alongside adjacent disciplines (proactive vs reactive):
Discipline Posture Uses Threat Hunting Proactive Manual analysis; intelligence information; TTPs Vulnerability Management Proactive Vulnerability feeds; automation & orchestration Incident Response Reactive Data analytics; automation - Threat hunting ≠ incident response.
-
1.4
Threat Hunting Goals
- Detect advanced threats in infrastructure — "routine/common" threats are often detected by monitoring, but advanced threats need proactive hunting:
- Nation-state actors
- Insider threats
- New/advanced malware
- Reduce time that attackers are in the network:
- Attempt to identify threats in early stages.
- Less time to cause damage, exfiltrate data, etc.
- Detect advanced threats in infrastructure — "routine/common" threats are often detected by monitoring, but advanced threats need proactive hunting: