Building a Hypothesis
Throughout this chapter, it has been stated that one of the main characteristics about threat hunting is that it is a human-driven activity and that it cannot be fully automated. At the core of this process is the generation of the hunt´s hypothesis, which refers to what are the threats to the organization environment in line with the threat hunter hunches and how to detect them. Hypotheses are partially based in observation, noticing deviations from the baseline and partially on information that could come from experience or from other sources.
The craft of the hypothesis is crucial to produce good hunts. A poorly defined hypothesis would lead to wrong results or conclusions. This most likely will have a negative impact on the organization since defense and visualization gaps are going to be missed and provide a safe passage to the adversary. The lack of adequate visualization is one of the organizations worst enemies, since it generates a false sense of security...