What is needed to conduct a successful threat hunt?
The most basic, and most common, version of a threat hunt can be conducted by a single employee with privileges and tools who is curious about some activity. This employee must also have the appropriate authority and access to additional information on the organization and from the internet. The size and scope of the team become irrelevant when talking about the most basic requirements needed to hunt on an enterprise. A successful threat hunt requires five specific items to be there.
- An organization that wants to have a threat hunt conducted
Out of all of the requirements, this is the most critical. Woe is the hunter that is tracking an adversary across an organization that does not care or wants the hunter there. Taken from experience, this always results in numerous questionable, but unverified, anomalies being found. Those anomalies are documented and reported to the organizational stakeholders who do not utilize...