Beginning a threat hunt does not require a good deal of planning, but there should be some structure as to how the threat hunt will be conducted, the sources of data, and the time period on which the threat hunt will focus. A brief written plan will address all of the key points necessary, and place all of the hunt team on the same focus area so that extraneous data that does not pertain to the threat hunt is minimized. The following are seven key elements that should be addressed in any plan:
- Hypothesis: A one- or two-sentence hypothesis that was discussed earlier. This hypothesis should be clearly understood by all the hunt team members.
- MITRE ATT&CK tactic(s): In the previous chapter, there was a discussion about the MITRE ATT&CK framework and its application to threat intelligence and incident response. In this case, the threat hunt should include...