Summary
Remember, there are three types of data collection. Input-driven data collection is about collecting everything possible, output-driven data collection involves collecting only what is known and important, and finally, hybrid data collection starts with collecting all the data and then quickly narrowing it down. Direct analysis is seeing something at the source that proves or disproves an occurrence. Secondary correlation is observing evidence outside of the target system and inferring what occurred.
When it comes to conducting this type of work, always automate correlation and analysis as much as possible in order to free up the team's primary resource: time. In the end, finding or not finding the adversary is not necessarily a sign of success. Stick to what the purpose of the threat hunt is, and the objectives laid out during planning.
In the next chapter, we will dive into what is produced by all of this data analysis – documentation. It is a good thing...