The hunting cycle
Before beginning a hunting cycle, there are a few things that need to be fully established. The threat hunters will need to understand the business needs and concerns that will be addressed throughout the life of the hunt. The scope and environment should be established with all stakeholders. Finally, the desired outcomes and deliverables should be agreed upon. Once these are in place, the team can begin its cycle.
Most of the threat hunting methodologies you can find look very similar to one another. They will all center around starting with a hypothesis or collection of hypotheses. However, this is only partly correct; a hypothesis should be driven by intelligence, awareness of the environment, and business requirements. Just because a threat hunting team identifies lateral movement on a particular portion of the network does not mean it is of significance to the team. The hypotheses for a hunt are scoped to the business requirements of the organization. If the...