MOA
Whatever written agreements might be called within an organization, there should always be a formalized and signed agreement between the hunt team and the organization's stakeholders who own and operate the target enterprise. In the case of a threat hunt, this typically starts with a formal request for assistance that allows for discussions to begin. This formal request can be as simple as an email to a sales mailbox, or a formal written request for proposal (RFP). Then, negotiations start to determine the resources that will be made available to the threat-hunt team. If those negotiations go well and a threat hunt is determined to be value-added and beneficial to the organization, then planning will begin.
Upon conclusion of planning, a deliverable is due to all parties in the form of a signed/approved plan that specifies all the requirements and expectations of the threat hunt. This is where the items that were painstakingly laid out, drilled, and refined in Chapter 7...