flâneur — a map of the web's best reading

Baseline Hunting with the PEAK Framework | Splunk

splunk.com · 2,751 words · saved by 1 readers

Baselines are an essential part of effective cybersecurity. They provide a snapshot of normal activity within your network, which enables you to easily identify abnormal or suspicious behavior. Baseline hunting is a proactive approach to threat detection that involves setting up a baseline of normal activity, monitoring that baseline for deviations, and investigating any suspicious activity. The PEAK Threat Hunting Framework identifies three types of hunts: In this article, let's take an in-depth look at baseline hunts, also known as Exploratory Data Analysis (EDA) hunts. (This article is part of our PEAK Threat Hunting Framework series. Explore the framework to unlock happy hunting!) Baselining can help you familiarize yourself with new datasets or environments where you've never hunted before. It serves as an excellent precursor to more focused hypothesis-based or model-assisted threat hunting. Before planning and scoping future hunts, it's important to understand the available data

Baseline Hunting with the PEAK Framework | Splunk Baseline Hunting with the PEAK Framework Security July 11, 2023 David Bianco Baselines are an essential part of effective cybersecurity. They provide a snapshot of normal activity within your network, which enables you to easily identify abnormal or suspicious behavior. Baseline hunting is a proactive approach to threat detection that involves setting up a baseline of normal activity, monitoring that baseline for deviations, and investigating any suspicious activity. The PEAK Threat Hunting Framework identifies three types of hunts: Hypothesis-

Explore this link on the map →

saved by

related reading