Beyond IOCs: Contextualized Leads from Analytics-Driven Threat Hunts | by Alex Teixeira | Detect FYI
In this post I will walk you through my thought process and share a concrete KQL hunting query for Defender for Endpoint as an example. When a team takes a list of Indicators of Compromise (IOC) and compares it against matching SIEM events, does it count as threat hunting at all? Whether you consider that hunting or not, in the end, assuming IOC hits as leads, that practice might as well be considered one step in the process. Nevertheless, in case you have a modern SIEM, there's no excuse for not fully automating this initial step, that is, the IOC matching itself. By automating near-real-time and retrospective scanning of IOCs, it will significantly improve your Hunting/Detection output — as long as you are able to manage and scope in a good list of IOCs. The idea here is to go beyond the pure Threat-Intel driven approach and generate more contextualized hunting leads based on simple analytics. If you need a quick killer reference about Threat Hunting, I enjoyed reading the following
Explore this link on the map →