Planned triggers
This has already been hinted at in several areas; however, it can be very helpful to have a portion of hunt planning dedicated to it. It's important to plan for things to go wrong or that need to be changed. These events are also referred to as triggers. Some generic instances of when a trigger might occur and a change in threat hunter behavior would be necessary to remain on a successful hunt are listed as follows:
- Illegal activity is identified.
- An automated adversary is identified.
- An interactive adversary is identified.
Each of these areas would trigger the hunt analyst to change their standard behavior and process into a different cycle. The communication contracts and deviation plan will help the analyst, the team lead, and the customer to understand what will occur in these types of situations.
For example, if an analyst came across potential evidence of illegal activity, the agreed-upon deviation would be for the analyst to stop...