skip to content

Threat Hunting

Proactive search for an adversary no alert has fired on: forming a hypothesis, learning what the estate normally does, reading the rare tail, and banking what the hunt produced.

on this pageshow

explore

questions

page 2 of 2

What do you put in front of an incident lead when handing over a live hunt finding with no enrichment?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

A one-line claim, the raw records with time range and timezone, the hypothesis and what would disprove it, your confidence and its basis, what is still live, what you already touched, and the specific decision you are asking for.

open as a page

Why do high-entropy DNS subdomain labels flag tunnelling and legitimate lookup services alike?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

High-entropy labels flag encoding, not intent: a tunnel packs payload into the leftmost labels, and reputation or anti-spam services pack a hash or an address there just as randomly. Attribution of the parent domain decides.

open as a page

Stack counting reads the rarest rows - what kind of intrusion hides in the common ones?

level: middleimportance: nice to knowfreq 34%

basics

~10 s

Anything the adversary made common or borrowed from something already common: an approved image whose entrypoint was overridden, persistence that automation deployed hundreds of times, or a value shared with heavy legitimate use.

open as a page

Half your WMI persistence hunt needs a human to read the consumer's command line. What do you promote?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Split it. Promote the half you can state as a decidable claim — a binding created outside the known management accounts — and keep the half that needs a human judgment on the command line as a documented recurring hunt. Encoding looks-suspicious as a keyword list buys a noisy rule and a false sense of coverage.

open as a page

How do you build a hunting baseline for an estate you cannot assume was clean?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

A baseline learned only from telemetry encodes whatever was already happening, so a long-resident intruder becomes normal. Cross it against intended state — inventory, image manifests, change records, account ownership — where a missing record beats any frequency.

open as a page

An executive reads your empty ESXi hunt and asks you to confirm the cluster is clean — what do you commit to?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Commit to the bounded statement, not the binary: what was searched, over which hosts, for how long, and what remains unsearched. Then convert the gap into a costed telemetry ask, because blind hosts can never yield a stronger answer.

open as a page

Your MDR provider owns the overnight queue and refuses your remote-access-tool rule — what do you do?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Treat the refusal as information. Whoever works the alerts must share tuning authority, and a provider without your deployment baseline genuinely cannot triage this. Fix the enrichment, keep it in-house with a named gap, or route it to application control.

open as a page

The Linux platform owner refuses your auditd collection requirement on cost — now what?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Shrink the ask to targeted rules on a defined host set, settle the overhead argument with a measured pilot rather than assertion, and offer cheaper alternatives. If it is still refused, record an accepted gap with a named owner and expiry, and reflect it in hunt reporting.

open as a page

The platform owner refuses your 12-month LSASS sweep on compute cost — how do you still run the hunt?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Scope before arguing: sample a slice to estimate hit density and cost, run one procedure variant at a time with the cheapest filter first, project only the fields you need, and spend the full window only on the low-volume variants.

open as a page

showing 31–39 of 39