QuestionQ7
Threat Hunting TechniquesA company’s Security Operations Center team identifies a successful VPN connection originating from a country outside its known countries of operation. Following the connection, the team receives multiple triggers from the same source IP address concerning file access and changes on the file server. The team determines that an unknown adversary has exfiltrated data through a compromised user account.
To identify other possible actions performed by the adversary, which type of threat hunting should be used?
Community Discussion