Chapter 11: Documentation
If it has not been clear thus far in this book, communication is an exceedingly important concept to understand at this point. Communication is key at each step of a threat hunt. If any member of the team and organization fails to effectively communicate, then they can cause the entire team and organization to incur a penalty, leading to a potential threat-hunt failure.
Communication in the short term can be accomplished in many different forms. However, long-term communication—for example, an understanding that will last more than an hour—needs to be recorded for future reference. Take to heart the following rule: If it isn't written down, then there is no evidence that it did or did not occur. This applies to everyone: threat-hunt team members, individuals in leadership roles, and organizational stakeholders.
While there are a large number of potential documentation areas that a team would want to document, things such as a daily...