Threat hunting
You can go hunting as part of an investigation, or you can hunt proactively based on available threat intelligence relevant to your organization. In this section, we’ll go over threat hunting using MDE and response actions you might take as the result of a hunt, including custom detection rules.
The threat hunters at Graves Corporation have now received a report of several devices with Raspberry Robin infections. The assigned Tier 3 threat hunter begins by reviewing threat analytics and other threat intelligence sources to gain a deeper understanding of the threat. They now need to perform a widespread investigation of the environment to gauge the full scope of the incident. To kickstart this investigation, the hunter goes to the same incident and alert that the previous tier was investigating, expands the process event where msiexec.exe
was reaching out to the internet, clicks the ellipsis next to the URL in the Referenced in commandline field, and clicks...