Software tools
When choosing software to utilize, there are a few things that the team will need to take into consideration:
- Team experience with toolsets for both using them and maintaining them.
- Existing capabilities inherit on the target network.
- Authorization to deploy new capabilities on the target network.
- Any known vulnerability or alternate uses of the toolset. Ensure that nothing being employed by the team or deployed on the network can be utilized by an adversary to their advantage.
- The perception intended to present to an adversary. Tanium showing up might not come across as defensive as it has a wide range of uses by maintenance, but a Carbon Black agent would raise suspicions as it is purely for defense.
Software is a place where some leaders can fall into a trap of thinking more is better. We have all heard people asking the question what else do you need? Piling more and more toolsets into a hunter's toolbox does not make them more...