Chapter 10: Importance of Documenting and Automating the Process
So far, we have learned what threat intelligence is, what threat hunting is, how to get started with atomic hunts, and how to use intelligence-driven hypotheses, as well as mapping them to log events and hunting for the adversary; but we still have the last remaining piece of the puzzle to cover: documenting and automating to update the hunting process.
In this chapter, we're going to cover the following main topics:
- The importance of documentation
- Updating the hunting process
- The importance of automation