Threat Hunting
From Socology.org - The Study of Security Operations
Revision as of 03:33, 29 October 2018 by Frankangiolelli (Talk | contribs)
This section is under development
Contents
Objective
The objective of Threat Hunting is a proactive search of systems for adversaries and compromise. Whereas Continuous Monitoring is a reactive service, Threat Hunting strives to actively search logs, controls, countermeasures and activity to identify signs of compromise before they are detected.
Hunting activity feeds several other services including Content Engineering, Continuous Monitoring, Log Management and Compliance and Risk Management.
Hunting also receives inputs from Threat Intelligence, Enterprise Intelligence and Risk Management.
Process
Tooling
- SIEM, log management or other log collection and analysis tools
- Data analytics tools