Development of Open Source-based Threat Hunting Platform
Denny Hermawan, Nugroho Ganda Novianto, Digit Octavianto · 2021
Threat hunting is a process that focuses on activities that are repeated in nature, by taking an approach to identify and understand threat actors who may have entered and are in the computer network infrastructure. It becomes the focus of the Central Security Operation Centers (SOCs) as a survey conducted by the SANS Institute on threat hunting, show 91% of enterprises reported increasing the implementation of threat hunting. Therefore, this research attempts to design a threat hunting platform using Elasticsearch, Logstash, and Kibana (ELK) by implementing rules and alerts obtained from sigma rules for attack detection and performing penetration testing using the Atomic Red Team method and Web Application Vulnerability to obtain attack logs. In the log mapping process, an analysis of the previously obtained attack detection was carried out. Then we create a threat hunting framework using MITRE ATT&CK, Pyramid of pain and Diamond Models of Intrusion Analysis. By getting the results of attack detection from 10 rules and alerts detected on ELK and obtaining 3 tactics and 4 attack techniques on the attack method with the Atomic Red Team, and on the Web Application Vulnerability we discover 2 tactics and 3 attacks.