Summary
It's important to understand that the difference between an IT, OT, and cloud environment will be critical. If the team does not have experience in OT environments, then simply stay away from them. Do not be hesitant to ask questions as requirements are flushed out. This will help ensure that the team members with adequate experience and the proper equipment are deployed in support of the threat hunt.
Design the equipment needed for the hunt around the requirements and the network design. Do not decide on what is needed based upon what the team currently has available to them. There are a lot of different software solutions available to a team, both free and commercial. Default to living off of the land and utilizing what is already there. Build up from that existing baseline of capabilities and sources, then expand as needed to include new functionality and sources. While adding new sensors to get direct access to a log source might be the best solution, does an existing...