The Relative Strengths of Threat (Detection|Hunting) | by VanVleet | Medium
This article is one in a series on Threat Detection. Here, I’ll attempt to disambiguate the terms “threat hunting” and “threat detection” and explore the areas where each practice has relative strengths. There are a lot of terms in the industry for the processes we use to prevent threats from impacting our networks. For me personally, there are 3 that seem to involve a lot of confusion about where one ends and the next begins: threat hunting, threat detection, and detection engineering. A few definitions from well-respected industry sources (added emphasis is mine): See any similarities there? No wonder we can’t figure out which one is which! All three terms essentially mean “an effort to find undetected threats in a network as soon as possible.” One could argue that the terms are practically synonymous. There IS a distinction between Threat Hunting and Threat Detection, but the massive overlap between them stymies efforts to define them in a way that clearly differentiates. There are
This article is one in a series on Threat Detection. Here, I’ll attempt to disambiguate the terms “threat hunting” and “threat detection” and explore the areas where each practice has relative strengths. There are a lot of terms in the industry for the processes we use to prevent threats from impacting our networks. For me personally, there are 3 that seem to involve a lot of confusion about where one ends and the next begins: threat hunting, threat detection, and detection engineering. A few definitions from well-respected industry sources (added emphasis is mine): See any similarities there?
Explore this link on the map →