Products for local defenders
Except in extreme circumstances, most hunts will be executed with the aid of local defenders that staff the front lines of network defense every day. Providing these individuals with usable deliverables during and after the conclusion of the hunt is a major boon for the customer and reflects well on the hunt team. Some common products that can be provided are as follows:
- Network maps and an overview of how they were acquired
- Queries that were used during the hunt, along with descriptions of the associated indicators they would identify
- A technical report outlining all of the steps that were taken by the threat hunt team
- The intelligence report that the threat hunt was based on, as well as subsequent updates
- Detailed descriptions of evidence that was found that's related to threat actor activity
- Mappings of findings in evidence and intelligence to the MITRE ATT&CK framework
- A list of recommendations for improvements...