Automating everything
There is a rule of thumb for anything in information technology, which is – if you have to do it more than once, then that task should be automated. When it comes to data analysis, the direction is no different. Whenever possible, push all of your relevant data into a SIEM for large-scale aggregation, correlation, and analysis. Manual analysis and correlation are extremely difficult and time-consuming. As the amount of data increases, this task becomes closer to impossible for a group of analysts to do efficiently without some form of automation.
By utilizing technologies such as a centralized SIEM, even if it is central only to the hunt team, tasks stop being repeated. After initial SIEM deployment, a hunt operator can build a custom query for identifying DNS command and control for a customer's network, lateral movement, or suspicious host logins if that data is ingested. From there, the data should be put into the SIEM that automatically runs...