What Is Cyber Threat Hunting?
Cyber threat hunting is a proactive cyber defence activity. This is in contrast to traditional threat management measures, such as firewalls, intrusion detection systems (IDS), malware sandbox, and SIEM systems, which typically involve an investigation of evidence-based data after there has been a warning of a potential threat.
Threat hunting has traditionally been a manual process, in which a security analyst sifts through various data information using their own knowledge and familiarity with the network to create hypotheses about potential threats, such as, but not limited to, lateral movement by threat actors.
To be even more effective and efficient, however, threat hunting can be partially automated, or machine-assisted, as well. In this case, the analyst uses software that leverages machine learning and user and entity behavior analytics (UEBA) to inform the analyst of potential risks. The analyst then investigates these potential risks, tracking suspicious behavior in the network. Thus, hunting is an iterative process, meaning that it must be continuously carried out in a loop, beginning with a hypothesis.
Vocabulary
proactive cyber defence – taking action to find and stop security threats before they can cause damage, rather than waiting for an attack to happen, “The company uses proactive cyber defence by searching for hidden bugs in their software every week.”
firewalls – security systems that act as a protective barrier to control the network traffic going in and out of a computer, “Our office firewalls block dangerous websites so employees do not accidentally download viruses.”
intrusion detection systems (IDS) – software tools that watch a network for malicious activities and send alerts when they find something suspicious, “The intrusion detection systems (IDS) sent an alert when someone tried to guess the admin password multiple times.”
SIEM systems – (Security Information and Event Management) software programs that collect and organize security data from across a whole company to help spot unusual activity, “The security team checks the SIEM systems to see a master list of everything happening on the network.”
hypotheses – informed guesses or theories that need to be tested to see if they are true, “The analysts came up with a few hypotheses about how the hacker managed to open the secret file.”
lateral movement – a technique where a hacker moves deeper into a network from one computer to another to find valuable data, “After breaking into the receptionist’s computer, the hacker used lateral movement to reach the main financial server.”
threat actors – individuals or groups of people who intentionally cause harm or steal data in the digital world, such as cybercriminals, “The government is trying to stop advanced threat actors from attacking the power grid.”
machine learning – a type of artificial intelligence where computers learn from data and improve over time on their own, “The email app uses machine learning to automatically figure out which messages are spam.”
user and entity behavior analytics (UEBA) – a tracking process that learns the normal habits of users and devices so it can spot any strange or unusual behavior, “Using user and entity behavior analytics (UEBA), the system caught an account logging in from two different countries at the same time.”
iterative process – a repetitive procedure where you repeat a cycle of steps to continuously improve or get closer to a goal, “Writing a book is an iterative process because you have to keep editing and rewriting each chapter.”
