What is threat hunting?
Before we look at the definition of threat hunting, let's clarify some misconceptions around the concept by stating what threat hunting is not. First of all, threat hunting is not the same as cyber threat intelligence (CTI) or incident response (IR), although it can be deeply related to them. CTI can be a good starting point for a hunt. IR could be the next step the organization follows after a successful hunt. Threat hunting also isn't about installing detection tools, although it can be useful to improve their detecting capabilities. In addition, it is not searching for IoCs in the organization's environment; instead, you will be looking for things that bypassed the detection systems that have been fed with IoCs. Threat hunting is not the same as monitoring either, nor running queries randomly on monitoring tools. But, most of all, threat hunting is not a task that can be performed only by a select group of experts. Of course, expertise matters...