Threat Hunting
Eric C. Thompson · Apress eBooks · 2020
Threat hunting is the process of taking indicators of malicious activity, developing a hypothesis of how that malicious activity might be occurring in the environment, and hunting for it. Threat hunting, like machine learning, may just seem like a new buzzword in the information security space, but it does have its place in security operations. Threat hunting is proactively looking for indicators of compromise present in artifacts. Many times, new indicators are uncovered during investigations or by research conducted by information security practitioners and shared through groups or news feeds. Ideally a process exists to incorporate new indicators into the monitoring and detection capabilities. For some indicators, it is important to review historical logs and data for existence of these indicators.