Summary
A purposeful and repeatable hunting cycle methodology is needed for a threat hunt team. Always build a hypothesis for a hunt off of business requirements and concerns; never build them off of the known datasets that are available. At the same time, ensure that you utilize a collection management framework to help the team choose the resources that are required to conduct an effective threat hunt.
Daily and post-hunt debriefs must occur if the team is to overcome obstacles and improve. Honesty and candid discussions will need to occur during these events. Visualization methods can work wonders throughout this entire process, so use the one that fits the environment and the teams' processes. Whatever is chosen, ensure that the entire team is using the same one. Finally, the MITRE ATT&CK Matrix can be leveraged in many different ways. Educate the team and organization on its employment as early as possible.
If it was not already clear from the previous chapters...