skip to content

How do you build a hunting baseline for an estate you cannot assume was clean?

level: seniorimportance: nice to knowfreq 30%

answer

  1. the data was never guaranteed clean
  2. long residence becomes your normal
  3. a longer window makes it worse
  4. compare against intended state
  5. unclaimed persistence beats rarity

basics

~20 s

A baseline learned only from telemetry encodes whatever was already happening, so a long-resident intruder becomes normal. Cross it against intended state — inventory, image manifests, change records, account ownership — where a missing record beats any frequency.

solid answer

~50 s

Learned normality has a structural flaw: it describes what the estate did, not what it was supposed to do. If an adversary has been resident for months, their scheduled task is a common process lineage and their destination is an ordinary egress endpoint, so the baseline actively protects them. The fix is not a longer window — that makes it worse — but a second, independent source of normal that does not come from observation: the software inventory, the golden-image manifest, the deployment tool's list of what it installs, the change record trail, the directory's record of which service accounts exist and what each is for, and a freshly imaged reference host. Then hunt the disagreement: things present in telemetry with no counterpart in intended state are interesting regardless of how frequent they are. And say plainly in your report that a hunt run against a self-learned baseline that found nothing has established nothing about the estate.

go deeper

for a junior

Be ready to state the core problem in one sentence: a baseline learned from the estate describes what it did, not what it should do, so anything already present becomes normal.

for a middle

Explain why a longer learning window worsens contamination, and name concrete intended-state sources — software inventory, image manifest, deployment records, change tickets, the directory's service-account list — that do not come from observing the running estate.

for a senior

Show how you sequence a hunt around the disagreement between observed and intended, why unclaimed persistence outranks rarity, and how you report what a hunt with no findings actually established, including where you had no coverage.

for a principal

Own the consequence for the programme: if hunting depends on intended-state records the organisation does not keep, the recommendation is to build that inventory, and you have to make the case for funding it against the hunts it would enable.

## The flaw in learned normality Every baseline built from an estate's own telemetry answers the question "what does this estate do?" Hunters use it as though it answered "what should this estate do?" Those are the same only if the estate was clean throughout the learning window, and that is exactly the assumption a hunt exists to question. The consequence is uncomfortable and specific. An adversary who has been resident for months is not an outlier in your data; they are part of your distribution. Their persistence mechanism has run on a schedule long enough to look like every other scheduled job. Their remote-access tooling appears under a parent process your baseline now considers ordinary. Their command-and-control endpoint has been contacted daily by the same set of hosts for a year, which any frequency-based view will read as thoroughly established. Lengthening the learning window makes this worse, not better: the longer the window, the more thoroughly resident activity is absorbed into normal. ## Bring in a source of normal that is not observation The way out is to stop treating the estate as the only authority on itself. Intended-state sources describe what somebody decided should exist, and they are produced by processes an adversary usually does not control: - **The software inventory and the golden-image manifest** — what is supposed to be installed on this class of host at all. - **The deployment and configuration system's own record** — what it installs, where, and on which schedule. - **Change records** — the approved reason a thing appeared, with a date and a requester. - **The identity directory** — which service accounts exist, who owns each, and what each is nominally for. An account nobody will claim is a finding no matter how busy it is. - **Scheduled-task and service inventories from a freshly imaged reference host** — a machine built today from the approved image is an uncontaminated statement of what a clean host of that class looks like. - **Vendor documentation** — what a management agent legitimately does, so you can tell its real behaviour from something wearing its name. The hunt is then over the **disagreement** between observed and intended: present in telemetry, absent from every intended-state source. That question has a different shape from rarity, and crucially it is not defeated by the adversary being frequent. It is defeated only if they can also write into your inventory, your change system and your directory — a much higher bar, and one worth knowing whether you have set. ## Choose the axis you baseline on carefully Some framings are more resistant to contamination than others. Consider the difference between how often something happens *in time* and how widely it occurs *across the population*. An adversary can easily make their own activity frequent on the hosts they hold, and considerably less easily make it consistent with the estate's provisioning story — present on exactly the hosts a deployment wave targeted, absent everywhere else, appearing on new hosts only when they were built. Baselining against the provisioning narrative rather than against raw counts asks a question the adversary has to work much harder to satisfy. (How the long tail of a frequency ranking is then reviewed is its own discipline and is covered separately.) ## Reason about who claims what A third lever is ownership. Learned normality has no notion of an owner; intended state does. For each persistent thing you find — a service account, a scheduled task, a listening service, a standing outbound connection — the question "who will put their name to this?" is often faster and more decisive than any statistic. Unclaimed persistence is the most productive category in this whole style of hunting, and it is entirely invisible to a frequency baseline. ## Be honest about what you established The hardest part is the reporting. A hunt conducted against a baseline derived from the estate itself, which found nothing, has established very little: the absence of a finding is not evidence of absence, because the method's blind spot is precisely long-resident activity. Write that down. State which sources of intended state you had, which you did not, and which parts of the estate you therefore could not make a claim about — the hosts with no inventory coverage, the accounts with no owner recorded, the segment whose telemetry does not reach you. That list is the most valuable artefact a clean hunt produces, because it is the honest description of where an intruder could still be sitting inside your definition of normal. ## Practical sequencing In a real engagement the order is usually: pull the intended-state sources first, because they are static and cheap; build the learned picture second; diff them; work unclaimed and unexplained items before rare ones; and where an intended-state source does not exist, say so rather than substituting frequency for it. Building the missing inventory is often the most valuable recommendation the hunt produces, and it is a recommendation about the estate rather than about any one alert.

  • An external destination has been contacted daily by forty hosts for a year. Does that frequency make it normal?
    It makes it consistent, which is a fact about the estate's history and not about intent. The useful question is whether any intended-state source accounts for it — a change record, the software inventory, a vendor's documented endpoint — and whether a team will claim it. Longevity is exactly what a resident adversary accumulates.
  • Why does extending the learning window make contamination worse rather than better?
    Because the window is what defines normal. A longer window absorbs more of a resident adversary's activity into the learned distribution, so the very thing you want to stand out becomes more established. Longer windows help with seasonality and business cycles; they do nothing for an assumption of cleanliness.
  • Your hunt against a learned baseline found nothing. What do you report?
    That no finding was produced, and what that does and does not mean. Name the method's blind spot — long-resident activity is inside the baseline — and list where you had no intended-state source, no inventory coverage or no telemetry. That gap list is the finding, and it is usually more actionable than a rare process pair.

Learning normal from the estate alone is like learning a language from one household — you speak their mistakes fluently and never hear them as mistakes.

saying these in an interview costs you the question

  • Assumes the learning window was free of adversary activity
  • Extends the window to make the baseline more trustworthy
  • Treats long-standing frequency as evidence of legitimacy
  • Reports a hunt that found nothing as proof the estate is clean
  • Has no intended-state source to compare telemetry against

context