March 2022
Intermediate to advanced
752 pages
18h 47m
English
In this chapter, we cover the following topics:
• Threat hunting basics
• Normalizing data sources with OSSEM
• Data-driven hunts using OSSEM
• Hypothesis-driven hunts using MITRE ATT&CK
• The Mordor project
• The Threat Hunter Playbook
What is threat hunting? Threat hunting is based on the assumption that an adversary is already in the network and you need to track them down. This is a topic that requires quite a bit of knowledge about (1) how adversaries operate and (2) how systems operate normally and when under attack. Therefore, this is a topic that cannot be covered fully in this chapter. However, we aim to give you an overview of the basics, from which you can expand over time. ...