惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
罗磊的独立博客
量子位
Jina AI
Jina AI
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
美团技术团队
雷峰网
雷峰网
爱范儿
爱范儿
S
SegmentFault 最新的问题
小众软件
小众软件
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
3 Threat Hunting Myths You Shouldn't Believe
Intel 471 · 2020-11-18 · via Intel 471 Blog

Introduction

Threat hunting activities can generate tremendous benefit for organizations, and not just in finding hidden active threats in the environment. When done regularly, threat hunting can feed SOC threat detection capabilities with additional detection content and improved telemetry about the tactics, techniques, and procedures (TTPs) of threat actors specifically targeting an organization's assets.

Often times this long trail of threat hunting ROI can be achieved even with a small investment of time and resources put into an emerging threat hunting program. Contrary to the mystique and misconceptions that have been built up around threat hunting, organizations don't necessarily need a super advanced program before they start reaping the benefits from running a hunt.

While higher levels of maturity, found in structured hunts, can certainly help threat hunters more regularly find the most advanced threats, every organization can benefit from simple hunts that are possible for a broad range of security teams. In order to battle these misconceptions about threat hunting and encourage more teams to dip their toes in the water, we want to bust three of the most common threat hunting myths prevalent within the security community.

Threat Hunting Myth #1: You Need to Have Indefinite Visibility at the Endpoint

Often times security teams are hesitant to begin threat hunting because they don't have complete or indefinite visibility into their endpoint assets. While endpoint logs certainly can be very valuable for threat hunting, they are definitely not a prerequisite for a wide range of hunts.

There's still a very large attack surface that can be detected from network logs, DNS logs, and information collected about network activity. If organizations are taking their first steps into threat hunting, network activity can provide a treasure trove of information to start digging in.

Threat Hunting Myth #2: Threat Hunting Success Depends on Sophisticated Techniques

Another common misconception is that threat hunting success depends upon very complex techniques and methods. Many times—often, in fact—simple techniques can detect a wide range of hidden threat behavior that can completely bypass existing security controls. There are some very common malicious techniques that a large body of attacks must complete in order to carry out their entire attack chain.

By focusing on commands and methods that dig up evidence of those common techniques, simple threat hunting activity can reap a lot of beneficial results. An example would be seeking out evidence of suspicious child processes from Microsoft Office tools. Things such as PowerShell, cmd.exe, rundll32.exe, and many others are a great way to look for attackers targeting users with phishing.

Threat Hunting Myth #3: You Need Analysts or Threat Hunters with Years of Experience

One of the big constraints for starting up a threat hunting team is that there aren't a whole lot of experienced threat hunters available for hire today. But a security team can bootstrap a basic threat hunting program using existing security analysts and a few simple tools.

These kinds of resources are great, and they can accelerate the yields of threat hunting activities, but at the base level, all that organizations really need is a knowledge of what activity looks normal and good on the network. With that solid baseline, it's possible to get started looking for anomalies, and perfect threat hunting techniques along the way.

If Nothing Else, Remember This Threat Hunting Tip…

The lesson from all of these busted myths should be that threat hunting is not an all-or-nothing affair. Yes, advanced threat hunting does take a higher level of sophistication and investment to achieve. But it's very worthwhile and beneficial to start getting out there and doing hunts any way that you can.

Don’t stop there, dig deeper in developing effective threat hunting in your organization by reading: Threat Content, Not Automation, Fuels Effective Threat Hunting.