Summary
We covered how critical communication is at each step of a hunt in the earlier chapters. If anything needs to persist, ensure that it is documented in a complete and verbose enough manner that the reader will understand the intent. There are three main approaches to TTP documentation—balance these approaches with the capability and maturity of the hunt team and the acceptable risk level of the target organization.
Each threat hunt will require its own agreement between the team and the customer. That agreement will need to be signed by the individual or individuals with the appropriate authority to grant permission for the requested activities. Do not hesitate to involve lawyers in this phase. Pre-approved actions should be outlined in the agreement. Do not skip this!
In the next chapter, we will begin discussing activities that happen during and after a hunt, along with deliverables. This is where the documentation discussed in this chapter comes into play, as...