Navigating Threat Hunting
Threat hunting, designed to detect unknown security incidents and vulnerabilities within an organization’s systems, allows an organization to augment its detection and prevention-focused security mechanisms and implement defense in depth.
Instead of digging into a known event or incident, threat hunters develop hypotheses about potential threats that their organization may be facing. These hypotheses may be based upon knowledge of the cyber threat landscape, the organization’s IT infrastructure, and other factors. Once a hypothesis has been developed, the threat hunter will evaluate it by collecting and analyzing data that could prove or disprove their hypothesis.
Priority Intelligence Requirements for Threat Hunting
A major challenge of threat hunting is the unrestricted scope and wide range of potential avenues of investigation. Threat hunters can pursue a variety of potential threats on many different systems. This vast number of potential combinations makes it necessary for threat hunters to prioritize the hypotheses that they test.
For this reason, it is vital for an organization to create priority intelligence requirements (PIRs) for their threat hunting program. These help to define which threats are the most important for threat hunters to investigate. These PIRs can then be used to develop hypotheses and guide the threat hunting process to maximize the value of the hunt to the investigation.
Step 1: Prepare The Essentials For The Hunt
Preparation is essential for a successful threat hunt. The three key components of a threat hunting program include:
- The Hunter: Threat hunting is a human-driven exercise designed to identify unknown intrusions or vulnerabilities in an organization’s systems based on evaluating hypotheses. Developing, testing, and evaluating these hypotheses requires knowledge and experience regarding the threats that an organization may face and how to identify these threats via a threat hunt.
- The Data: The goal of threat hunting is to prove or disprove a hypothesis regarding a potential threat to the organization or a previously undiscovered vulnerability. Proving or disproving this hypothesis requires access to data that enables the threat hunter to make a definitive decision. In preparation for future threat hunting, an organization needs to put processes and solutions in place to collect the data required to evaluate hypotheses derived from an organization’s PIRs.
- The Tools: Threat hunting requires in-depth data collection and analysis. While threat hunters may collect and analyze this data manually, doing so could be time-consuming and prone to errors. Maximizing the efficiency and effectiveness of a threat hunting program requires tools that can help hunters to better collect, analyze, and interpret data to prove or disprove their hypotheses. You’re welcome to jump right into your proactive threat hunt with our Investigative Portal.
Step 2: Define Your Threat Hunt
A threat hunt begins as a hypothesis about a potential undetected vulnerability or intrusion within an organization’s systems. After preparing for the threat hunt, the next step is to define the hypothesis for the threat hunt. A threat hunting hypothesis should be based on an organization’s PIRs and threat intelligence. Over time, a threat hunting program should test hypotheses for each potential threat that aligns with an organization’s PIRs.
For example, if an organization is concerned about ransomware attacks, threat hunters might focus on testing hypotheses regarding common ransomware infection vectors, such as if an attacker has exploited a virtual private network (VPN) vulnerability or used compromised credentials to log in via remote desktop protocol (RDP). Alternatively, threat hunters could look for indications of a ransomware infection on a system, such as encryption of files, detection of known ransomware variants, or attempts by the malware to move laterally to infect other corporate systems.