Data collection mindsets
There are three typical mindsets when it comes to how a team plans on collecting data during a threat hunt as well as the general day-to-day defense of a network. They are as follows:
- Input-driven: Collect everything possible. If it has logs, then collect them and store them somewhere. The initial deployment of this method is low-effort as it just requires the added step of collecting existing logging. The downside of this mindset is that a defender can quickly be overloaded with information that does not matter.
- Output-driven: Collect and store only specific data that is known to the team and that they care about. This is a very tailored approach and requires the defender to know what to look for. While it is easy for an analyst to digest this method, they will immediately miss anything that is unknown to them without the ability to go back and retrieve it. This means if an incident responder or hunt analyst needs to review data that is not there...