Ways to organize a team
As with many things in threat hunting, a team's organization will be dependent upon many different factors. Some organizations have a rigid structure mandated from the top down on how project teams will be organized. Some might have certain requirements and priorities that give extra flexibility when forming a team. Regardless of whether a team is coming in as a third party or organic to an organization, certain criteria must be taken into account.
When organizing a team, keep in mind that you can combine roles and responsibilities. If you decide to combine functions, walk through the impacts that the decision will have and ensure it is something that the team can work with.
For example, we can look at what would happen if we had a single team member acting as both a host-based analyst and a server administrator. This would result in an individual that is expected to both utilize and maintain the tools that the team employs. When a part of the hunt...