✳flâneur — a map of the web's best reading
More on Threat Hunting
taosecurity.blogspot.com · 835 words · saved by 1 readers
Richard Bejtlich's blog on digital security, strategic thought, and military history.
More on Threat Hunting Get link Facebook X Pinterest Email Other Apps November 23, 2018 Earlier this week hellor00t asked via Twitter : Where would you place your security researchers/hunt team? I replied : For me, "hunt" is just a form of detection. I don't see the need to build a "hunt" team. IR teams detect intruders using two major modes: matching and hunting. Junior people spend more time matching. Senior people spend more time hunting. Both can and should do both functions. This inspired Rob Lee to blog a response, from which I extract his core argument: [Hunting] really isn’t, to
Explore this link on the map →saved by
related reading
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Honeypot (computing) - Wikipediaen.wikipedia.org
- Mediumkostas-ts.medium.com