Scenario A – internal threat hunt
The Federal Bureau of Investigation (FBI) notified Widget Maker Inc's management of a phishing campaign targeting several employees at strategic business locations globally. The investigator explained that a foreign entity began a campaign 4 months ago targeting companies within the United States with government contracts to build advanced artificial intelligence capabilities. They also stated several systems within the company's public address space had been sending beaconing network traffic to a known command and control server associated with the campaign.
With the company's intellectual property at stake, the Chief Executive Officer (CEO) authorized the establishment of a permanent threat hunting team utilizing internal resources from the SOC and Network Operations Center (NOC). With the knowledge of subject matter experts, the data provided by the FBI, and intelligence gained through open source intelligence, the threat...