Protecting the team's equipment
Protecting the team's hardware can range from defending against the innocent passerby that accidentally turns off equipment to the malicious insider that is actively attempting to sabotage the threat hunt. As previously mentioned, having a secure war room is the first step to enabling this protection. This place could be a hotel room or conference area that only the team has access to.
Some potential requirements to take into consideration for this area are the following:
- Secure access limited to the threat hunting team and cleared personnel
- Ability to prevent cleaning crews and other third-party entities from entering the space
- After-hours security if not operating 24/7 throughout the hunt
- Adequate bandwidth to the network
- Adequate and secure bandwidth for open source research
- Ample power for all equipment
- Ample cooling for all equipment and personnel
Understand that a location being selected as a...