Success factors
This portion of planning is what separates the teams that did things and the ones that did things that matter. It is the simple act of outlining the requirements to include the tasks and objectives that will be measured against to quantify whether the hunt was a success.
A measurement of performance (MOP) attempts to determine the following: did the analyst perform the action correctly? If the action was to review network data between a certain period, then the MOP would ask the following question: did the analyst review the data in that period? MOPs have yes or no answers and are, typically, very straightforward in meaning with no wiggle room for interpretation. Each MOP is directly tied to a task, or a group of tasks, performed by the hunt analyst. Those tasks will always be directly linked to answering questions for one of the hypotheses. If this chain of logic is ever broken, this is a sign that the resources on the team are being wasted.
A measurement of...