QuestionQ7

Threat Hunting Techniques

A company’s Security Operations Center team identifies a successful VPN connection originating from a country outside its known countries of operation. Following the connection, the team receives multiple triggers from the same source IP address concerning file access and changes on the file server. The team determines that an unknown adversary has exfiltrated data through a compromised user account.

To identify other possible actions performed by the adversary, which type of threat hunting should be used?

Explanation

Structured threat hunting uses known indicators and a specific hypothesis to investigate related adversary behavior. The anomalous VPN connection, common source IP address, compromised account, and suspected data exfiltration provide the defined starting point needed to trace additional activity. Microsoft describes threat hunting as hypothesis-based analysis used to prove or disprove a suspected breach.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!