惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
腾讯CDC
J
Java Code Geeks
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
美团技术团队
云风的 BLOG
云风的 BLOG
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
U
Unit 42
雷峰网
雷峰网
B
Blog RSS Feed
博客园_首页
量子位
F
Fortinet All Blogs
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Check Point Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Threat Hunting and You: Why Content is Critical to Threat...
Intel 471 · 2020-03-10 · via Intel 471 Blog

In a changing and evolving threat landscape, how can you detect the unknown and mitigate the constant risk of breaches? Countless organizations have claimed to have the answer to this age-old dilemma by utilizing new technologies such as Machine Learning or Artificial Intelligence – however, one solution in the recent years, known as “Threat Hunting”, has proven to be particularly effective.

[hubspot type=cta portal=7924572 id=d13ae3c6-78f8-41f8-b5a8-1975460104dd]

WHAT IS THREAT HUNTING?

Many organizations and individuals have defined threat hunting in one way or another, but Sqrll (an organization that specialized in threat hunting, which was later acquired by Amazon Web Services in 2018) summarized it well and succinctly in their white paper “A Framework for Cyber Threat Hunting”. They defined it as “the process of proactively and iteratively searching through networks to detect and isolate advanced threats that evade existing security solutions” (Sqrll, 2018).[1]

To provide an example of this in action, and highlight some of its downfalls, suppose your security team proactively initiates an assessment of your Active Directory environment for anomalous account activity and identifies a large amount of Windows Event Logs indicative of a Successful Login (EventID 4624), with a Logon Type 10 (Remote Interactive Login – this occurs when a user logs in via terminal services, remote assistance, or remote desktop). In doing so, they were exercising a core component of Threat Hunting – proactivity. In comparison to passively waiting for an alert to trigger due to the Windows Event Logs hitting a specified threshold, they proactively searched for the potential “bad.”

To further complicate this example, what if they found out that the account responsible for generating the Remote Interactive Login events belonged to the Domain Administrators group? Would they know what implications that could have, or what steps they should follow to contain, mitigate, and remediate any potential compromise or breach? It is in this that we see a downfall of threat hunting – because of individuals varying experience, knowledge, or aptitude, your security team may not know what to make of that large amount of Windows Event logs, or even be able to find the “bad” in the mountain of logs.

WHY IS CONTENT NEEDED?

Many enterprises do not have the resources available to build a threat hunting team, or even to effectively perform threat hunting at the levels they would like to. Because of this, they greatly rely on the generic content built into their SIEMs or other tool solutions, which is often prone to false-positives and lacks contextualized or enriched information to accompany it to assist in the investigational process – it merely provides a simple alert name and expects the analyst to decipher the proprietary naming schema. While many organizations aspire to achieve advanced threat hunting, they often still depend on alerts based on reactive security tools that are dedicated to finding the most obvious threats based on unsophisticated or generic rules/signatures or content. They don’t have the time or ability to generate advanced content to proactively attain a much deeper insight into the data being generated in their environment – that leaves the most dangerous threats still active in their systems. Often the greatest threat facing your organization is not the advanced nation state, but rather the lowly trojan that runs rampant throughout your network undetected due to not having proper detections in place, or the context to enable your analysts to respond effectively.

HOW CAN CYBORG SECURITY HELP?

Cyborg specializes in the detection of adversarial toolsets and techniques. With decades of cumulative threat hunting, intelligence, and incident response experience, we have taken our knowledge of dealing with threat actors throughout Government, Defense, Technology, Healthcare, Media, and more, and developed the HUNTER threat hunting platform. This platform provides you with contextualized, enriched, and validated detection logic to detect even the stealthiest of adversaries. In all our content, we include full playbooks, mitigation recommendations, and more, to enable your analysts to quickly and efficiently review, respond, and react to any anomalous events in your environment.

To learn more about Cyborg and the HUNTER platform, please contact us.

[1] https://www.threathunting.net/files/framework-for-threat-hunting-whitepaper.pdf

Download the Whitepaper!