Chapter 7: Planning
At this point, every piece that is required for a successful threat hunt has been identified. Now it is time to put all of the pieces together. In doing so, the team will quickly move from thinking we really need to do this to a place that will allow them to say we did this right.
In Chapter 5, Methodologies, the hunting cycle was discussed with the starting point of identifying requirements. These are the business needs and concerns that are the origin of the threat hunt. What are the items that the organizational leadership is concerned with? What are the network administrators and defenders seeing that is of concern? What is being targeted online that is similar to our organization? Is there a critical software vulnerability in some dependency the organization might be using?
All of these items should be prioritized and approved by the requesting organization. The goal is to start planning with all the stakeholders on the same page as far as what the requirements...