Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunk
Welcome to another entry in our PEAK Threat Hunting Framework and we are taking our detective theme to the next level. Imagine a tough case where you need to call in a specialized investigator — even Sherlock depended on Watson from time to time! For these unique cases, we can use algorithmically-driven approaches called Model-Assisted Threat Hunting (M-ATH). In this article, we’ll look at M-ATH in detail. This method uses algorithms to find leads for threat hunting, enabling more advanced and experimental hunts. These methods include machine learning approaches like clustering, classification, or anomaly detection. (This article is part of our PEAK Threat Hunting Framework series. Explore the framework to unlock happy hunting!) The PEAK Framework identifies three primary types of hunts: Hypothesis-Driven Hunts, Baseline Hunts, and Model-Assisted Threat Hunts (M-ATH). M-ATH is categorized separately because it can facilitate baselining or hypothesis-driven hunting. Defining the advers
Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunk Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework Security May 17, 2023 Ryan Fetterman Welcome to another entry in our PEAK Threat Hunting Framework and we are taking our detective theme to the next level. Imagine a tough case where you need to call in a specialized investigator — even Sherlock depended on Watson from time to time! For these unique cases, we can use algorithmically-driven approaches called Model-Assisted Threat Hunting (M-ATH) . In this article, we’ll look at M-ATH in detail. This method uses al
Explore this link on the map →saved by
related reading
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- More on Threat Huntingtaosecurity.blogspot.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Unsupervised Machine Learning with Splunk: the cluster command | by Alex Teixeira | Detect FYIdetect.fyi
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Claude Mythos Preview System Cardwww-cdn.anthropic.com
- Elevating Security Intelligence with Splunk UBA's Machine Learning Models | Splunksplunk.com