Pre-approved actions
All actions that the hunt team will take will fall into one of three categories, as follows:
- Normal activities: These are low-threat, routine, typical daily actions—an example of this is an operator reviewing data collected overnight that was automatically ingested into the security information and event management (SIEM) device. These types of activities typically carry with them a low risk to the data, the enterprise, and the threat-hunt operation. No additional approval is needed from the customer or the lead before an operator performs them.
- Pre-approved actions: These are actions that increase overall risk (exposure, detection, the risk to the network, and so on) and require notification to the team's leadership that they were or are about to be executed. Depending upon the agreement with the client, these actions might also require notification to the organizational stakeholders that they were executed. An example could be interacting...