Scenario A – internal threat hunt
Widget Maker's team started compiling activities they wished to conduct during the hunt early on in the planning phase. These were gleaned from online sources (for example, https://www.sans.org/white-papers) and in the individual training and studying team members had done on their own. The team lead developed a template to start recording all these activities so that they could be standardized. However, there wasn't enough time between when this collection and documentation started, and the hunt needed to start.
The MOA that was shared between the stakeholders and the team included general tactics the hunt team would take, and from that selection, a few were explicitly approved, forming the basis for pre-approved actions the team could take. All other activities had to be presented to the team lead and get approved before being allowed to be conducted on the network. That approval process was not documented in the MOA, and during...