Chapter 13: Threat Hunt Scenario 3 – Suspicious External Connections
In this chapter, we are going to perform the third and final threat hunting exercise in the series of the three threat hunting scenarios that, as we discussed in Chapter 10, Threat Hunting, help assess the cybersecurity hygiene of a new or additional Industrial Control System (ICS) network (segment). By defining the following three threat hunting hypotheses, There are malicious actors (trying) to beacon out to external IPs/domains, There are malicious or unwanted applications running on assets in the industrial environment, and There are suspicious external connections going into the industrial environment, and performing threat hunting exercises around those hypotheses, we are trying to uncover as much malicious activity as we can when faced with adopting or integrating a new ICS network or the addition/expansion of an existing ICS network. The idea is that by performing these three threat hunting exercises...