Baseline Hunting with the PEAK Framework | Splunk
Baselines are an essential part of effective cybersecurity. They provide a snapshot of normal activity within your network, which enables you to easily identify abnormal or suspicious behavior. Baseline hunting is a proactive approach to threat detection that involves setting up a baseline of normal activity, monitoring that baseline for deviations, and investigating any suspicious activity. The PEAK Threat Hunting Framework identifies three types of hunts: In this article, let's take an in-depth look at baseline hunts, also known as Exploratory Data Analysis (EDA) hunts. (This article is part of our PEAK Threat Hunting Framework series. Explore the framework to unlock happy hunting!) Baselining can help you familiarize yourself with new datasets or environments where you've never hunted before. It serves as an excellent precursor to more focused hypothesis-based or model-assisted threat hunting. Before planning and scoping future hunts, it's important to understand the available data
Baseline Hunting with the PEAK Framework | Splunk Baseline Hunting with the PEAK Framework Security July 11, 2023 David Bianco Baselines are an essential part of effective cybersecurity. They provide a snapshot of normal activity within your network, which enables you to easily identify abnormal or suspicious behavior. Baseline hunting is a proactive approach to threat detection that involves setting up a baseline of normal activity, monitoring that baseline for deviations, and investigating any suspicious activity. The PEAK Threat Hunting Framework identifies three types of hunts: Hypothesis-
Explore this link on the map →saved by
related reading
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- More on Threat Huntingtaosecurity.blogspot.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Mediumdetect.fyi
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu