Scenario A – internal threat hunt
The threat hunt progresses for the new team, as built by Widget Maker Inc. Hypotheses are tested, some are proved to be true, and others are discarded or modified based on new criteria. Eventually, the primary objectives of determining the applicability of the FBI's notification and improving the defenses for intellectual property are completed. Now, it is time to develop the final deliverables for the report to give to the interested parties.
Early on in the threat hunt, the stakeholders made it clear that they wanted both a leadership report and a technical report. Because of this, the team lead has been working with stakeholders on a template based on the end-of-day updates, so their familiarity with them will improve the team's understanding. The technical reports will follow the format of similar reports that have been utilized in the SOC.
The leadership report is written mostly by the team lead, with some assistance from...