Summary
Understanding an organization's requirements and underlying motivations will be critical in conducting a successful threat hunt. Each organization will have its own business priorities, concerns, and regulatory and legal requirements. A team must firmly grasp these before progressing down the path of conducting a threat hunt. One such way to do this is to utilize the CSF developed by NIST. This is a great framework that allows anyone from a small team to an entire organization to outline their needs and priorities.
Use the organization's goals and needs to make sure resources are being applied in the areas that matter the most. Understand and communicate with stakeholders what type of threat hunt you want to conduct and what the organizational environment is capable of supporting. With the overview of addressing and scoping hunts to business needs and requirements completed, the next area for focus is how the team is constructed. In the next chapter, we will look...