What is Threat Hunting?
Before getting into a definition of threat hunting, let’s clarify some misconceptions around the concept by stating what threat hunting is not. First of all, threat hunting is not the same as Cyber Threat Intelligence (CTI) or Incident Response (IR), although it can be deeply related to them. CTI can be a good starting point for a hunt. IR could be the next step the organization follows after a successful hunt. Threat hunting also isn’t about the installation of detection tools, although it can be useful to improve their detections. In addition, it is not searching for IoCs in the organization’s environment, precisely; you will be looking for things that bypassed the detection systems fed with IoCs. Threat hunting is not the same as monitoring either, or running queries randomly on monitoring tools. But, most of all, threat hunting is not a task that can be performed only by a selected group of experts. Of course expertise matters, but it does...