Using observations to perform targeted hunts
As we explored in the previous section, using an Elastic Agent to detect and track malware samples is a great way to collect observations and security events that are happening on a system. However, what happens when we want to search through historic data to identify any previously infected systems? We can use the information we've collected to identify previously undetected infections.
There are several reasons as to why a system might have been infected without detection. It could be as simple as the system not having an Elastic Agent on it, the malware sample could be using bleeding-edge capabilities to evade detection at the time of infection, or it could also be that an alert just wasn't responded to.
Now that we've identified some malware samples on the victim machine, let's discuss the process to use that metadata to identify additional infections.
Pivoting to find more infections
Now that we've...