In-band versus out-of-band
An in-band connection for a threat hunting team means that the threat hunters' equipment will be connected directly to the target network. All communication traverses the same network that they are hunting on. A threat hunter will be able to sit at their workstation and remotely connect to an endpoint (for example, a server) to download logs or do live hunting. The pro and con of this type of connection are as follows:
- Pro: Extremely easy to establish with the least amount of effort.
- Con: Extremely noisy to the adversary; any attempt to measure the baseline activity of the target network will be different from how it truly looks as it will not include traffic and activity from the threat hunt team.
An out-of-band connection means that only a limited number of listening devices will be connected to the physical target network. All other equipment and communication will take place on a network isolated from the target. A threat hunter...