Building a hypothesis
Throughout this chapter, it has been stated that one of the main characteristics of threat hunting is that it is a human-driven activity and that it cannot be fully automated. At the core of this process is generating the hunt's hypothesis, which refers to the threats to the organization's environment that are in line with the threat hunter's hunches and how to detect them. Hypotheses are partially based on observation, where we notice deviations from the baseline, and partially on information, which could come from experience or from other sources.
Crafting the hypothesis is crucial to producing good hunts. A poorly defined hypothesis will lead to wrong results or conclusions. This will most likely have a negative impact on the organization since defense and visualization gaps are going to be missed and provide a safe passage to the adversary. Having a lack of adequate visualization is an organization's worst enemy, since it generates a...