Summary
Organizations are having to remodel their approaches to IR due to rapidly changing attack sophistication and threat-preparedness requirements. To begin with, organizations are moving towards threat hunting to be able to find threats that are not detected by security tools. It has become a fact that security tools cannot prevent all threats from happening, as some stealthy attacks can manage to pass through layers of security defenses. Threat hunting normally involves the identification of anomalies in an environment that can suggest the presence of a threat.
Further, to replace the traditional red team/blue team penetration testing perspective, organizations are moving towards purple teaming and synthetic war-gaming to improve the skills of their security professionals by simulating an attack environment and testing participants' skills in an active scenario. The end goal is usually to make sure that the security experts can use the available resources to mitigate...