flâneur — a map of the web's best reading

Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunk

splunk.com · 2,533 words · saved by 1 readers

Welcome to another entry in our PEAK Threat Hunting Framework and we are taking our detective theme to the next level. Imagine a tough case where you need to call in a specialized investigator — even Sherlock depended on Watson from time to time! For these unique cases, we can use algorithmically-driven approaches called Model-Assisted Threat Hunting (M-ATH). In this article, we’ll look at M-ATH in detail. This method uses algorithms to find leads for threat hunting, enabling more advanced and experimental hunts. These methods include machine learning approaches like clustering, classification, or anomaly detection. (This article is part of our PEAK Threat Hunting Framework series. Explore the framework to unlock happy hunting!) The PEAK Framework identifies three primary types of hunts: Hypothesis-Driven Hunts, Baseline Hunts, and Model-Assisted Threat Hunts (M-ATH). M-ATH is categorized separately because it can facilitate baselining or hypothesis-driven hunting.  Defining the advers

Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunk Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework Security May 17, 2023 Ryan Fetterman Welcome to another entry in our PEAK Threat Hunting Framework and we are taking our detective theme to the next level. Imagine a tough case where you need to call in a specialized investigator — even Sherlock depended on Watson from time to time! For these unique cases, we can use algorithmically-driven approaches called Model-Assisted Threat Hunting (M-ATH) . In this article, we’ll look at M-ATH in detail. This method uses al

Explore this link on the map →

saved by

related reading