Skip to the content.

Threat Hunting

Definition

A cyber security technique designed to detect presence of threat that have not been discovered by a normal security monitoring.

Phases of Threat Hunting

Establishing a hypothesis

A hypothesis is derived from the threat modeling and is based on potential events with higher likelihood and higher impact.

Profiling Threat Actors and Activities

Involves the creation of scenario that show how a prospective attacker might attempt an intrusion and what their objectives might be.

Actual Threat Hunting

Threat hunting relies on the usage of the tools developed for regular security monitoring and incident response.

Threat hunting consumes a lot of resources and time to conduct, but can yield a lot of benefits.

Threat Hunting vs. Normal SOC Monitoring


Back to main page