10 Importance of Documenting and Automating the Process

Join our book community on Discord

https://packt.link/SecNet

So far, we have learned what threat intelligence is, what threat hunting is, how to get started with atomic hunts, and how to use intelligence-driven hypotheses, as well as mapping them to log events and hunting for the adversary; but we still have the last remaining piece of the puzzle to cover: documenting and automating to update the hunting process.

In this chapter, we're going to cover the following main topics:

  • The importance of documentation
  • Updating the hunting process
  • The importance of automation

The importance of ...

Get Practical Threat Intelligence and Data-Driven Threat Hunting - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.