Authorities
The requirement for clear authorities to work in a client's network can make or break any hunt team. Determining authorities is the responsibility of the team lead to ensure the threat hunt is legitimate and approved on an infrastructure identified for activities.
Just because someone says that you can do something does not mean that you can do that thing.
Sometimes, this rather simple concept can be one of the most difficult parts of a threat hunt. It can be extremely difficult to figure out who has the authority to grant permission to perform threat-hunt actions. The requirement for formal and written permission is to agree that hunt team members won't be going to jail for approved activities. While this might sound like a far-fetched scenario, it is not.
Real-World Example
In 2019, an Iowa-based cybersecurity organization was contracted by the state to conduct penetration tests of some of their municipal facilities, including a courthouse. During...