Threat Hunting
Proactive search for an adversary no alert has fired on: forming a hypothesis, learning what the estate normally does, reading the rare tail, and banking what the hunt produced.
on this pageshowhide
explore
- Framing The Question11 questions
- Falsifiable Hypotheses3 questions
- Hunt, Rule Or Ticket4 questions
- Telemetry Preflight4 questions
- Finding The Abnormal16 questions
- Knowing Normal4 questions
- Stack Counting4 questions
- Technique Over Tool4 questions
- Reading Encrypted Egress4 questions
- Banking The Result12 questions
- Finding Nothing4 questions
- From Query To Rule4 questions
- When The Hunt Hits4 questions
questions
page 2 of 2What do you put in front of an incident lead when handing over a live hunt finding with no enrichment?
basics
~20 sA one-line claim, the raw records with time range and timezone, the hypothesis and what would disprove it, your confidence and its basis, what is still live, what you already touched, and the specific decision you are asking for.
Why do high-entropy DNS subdomain labels flag tunnelling and legitimate lookup services alike?
basics
~20 sHigh-entropy labels flag encoding, not intent: a tunnel packs payload into the leftmost labels, and reputation or anti-spam services pack a hash or an address there just as randomly. Attribution of the parent domain decides.
Stack counting reads the rarest rows - what kind of intrusion hides in the common ones?
basics
~10 sAnything the adversary made common or borrowed from something already common: an approved image whose entrypoint was overridden, persistence that automation deployed hundreds of times, or a value shared with heavy legitimate use.
Half your WMI persistence hunt needs a human to read the consumer's command line. What do you promote?
basics
~20 sSplit it. Promote the half you can state as a decidable claim — a binding created outside the known management accounts — and keep the half that needs a human judgment on the command line as a documented recurring hunt. Encoding looks-suspicious as a keyword list buys a noisy rule and a false sense of coverage.
How do you build a hunting baseline for an estate you cannot assume was clean?
basics
~20 sA baseline learned only from telemetry encodes whatever was already happening, so a long-resident intruder becomes normal. Cross it against intended state — inventory, image manifests, change records, account ownership — where a missing record beats any frequency.
An executive reads your empty ESXi hunt and asks you to confirm the cluster is clean — what do you commit to?
basics
~20 sCommit to the bounded statement, not the binary: what was searched, over which hosts, for how long, and what remains unsearched. Then convert the gap into a costed telemetry ask, because blind hosts can never yield a stronger answer.
Your MDR provider owns the overnight queue and refuses your remote-access-tool rule — what do you do?
basics
~20 sTreat the refusal as information. Whoever works the alerts must share tuning authority, and a provider without your deployment baseline genuinely cannot triage this. Fix the enrichment, keep it in-house with a named gap, or route it to application control.
The Linux platform owner refuses your auditd collection requirement on cost — now what?
basics
~20 sShrink the ask to targeted rules on a defined host set, settle the overhead argument with a measured pilot rather than assertion, and offer cheaper alternatives. If it is still refused, record an accepted gap with a named owner and expiry, and reflect it in hunt reporting.
The platform owner refuses your 12-month LSASS sweep on compute cost — how do you still run the hunt?
basics
~20 sScope before arguing: sample a slice to estimate hit density and cost, run one procedure variant at a time with the cheapest filter first, project only the fields you need, and spend the full window only on the low-volume variants.
showing 31–39 of 39