Hunts
A hunt team will be tasked with discovering IOCs and APTs. The goal will be to discover previous attacks and attacks in progress and prevent future attacks by gathering threat intelligence. Forensics techniques and access to historical logged data can be used.
Developing countermeasures
Once security professionals have identified tactics, techniques, and procedures (TTPs), we can use this information to build better defenses. Known blocks of bad actor IP addresses can be blocked, rules can be updated on Network Intrusion Prevention (NIP), Remote Triggered Blackhole (RTBH) rules can be created, as well as many other countermeasures.
Deceptive technologies
There are tools and technologies that can be used to delay or divert attackers while at the same time gathering useful threat intelligence. This includes the following techniques.
Honeynet
A honeynet is a collection of systems and services set up to simulate a vulnerable network. The goal will be to divert the...