The Threat Hunting Maturity Model
The composition of the threat hunting team and the time dedicated to the hunting activity is going to be determined by the size and needs of your organization. When there is no budget for a dedicated team, the time for the hunt is going to come out from the work schedules of other security analyst. In this scenario, the analysts usually are part of the SOC or of the Incident Response team.
So, if the team has limited resources, in order to carry out a successful threat hunting program it is necessary to carefully plan and prepare the hunt, combine process and experiences with a great knowledge on the tools, the techniques and the technology we are using Here is where David Bianco’s Threat Hunting Maturity Model can help us determine where are we standing and what do we need in order to grow the threat hunting team.
Determining Your Maturity Model
All organizations can do threat hunting, but in order to do it effectively they must invest in the...