Scenario A – internal threat hunt
The first threat hunt is truly complete – all the deliverables have been handed in and the team is ready to take a good break and work on improving their specific areas for next time, based on what each member feels is important. But the team leader for Widget Maker Inc.'s newest security section realizes that the final debrief, or feedback, is required for the threat hunt to be a full success.
The team lead communicates with the team and lets them know they'll spend at least the next 2 days going through this feedback together. This includes the network administrator, who thought they got out of the requirement and would be going back to the IT section. The team lead asks for and gets a volunteer as a timekeeper and gets some ideas for lunch and snacks for the next 2 days.
The team will do the feedback in the same space they conducted the hunt in. This will allow them to continue to control access, as well as using the...