January 2020
Intermediate to advanced
448 pages
11h 42m
English
New indicators that are identified during the threat hunt may force the modification of the existing threat hunt hypothesis. For example, in the course of a threat hunt for indicators of an Emotet infection, threat hunters uncover the use of the Windows system internal tool PsExec, to move laterally in the internal network. From here, the original hypothesis should be changed to reflect this new technique, and any indicators should be incorporated into the continued threat hunt.
Another option available to threat hunters regarding new indicators that are discovered is to begin a new threat hunt, utilizing the new indicators as the initiating event. This action is often leveraged when the indicator or TTP ...
Read now
Unlock full access