Detect FYI

Threat Detection Engineering and DFIR Insights

Follow publication

Member-only story

Beyond IOCs: Contextualized Leads from Analytics-Driven Threat Hunts

Alex Teixeira
Detect FYI
Published in
8 min readNov 5, 2023

--

Crafting an analytics-driven hunting query

From SANS whitepaper: “Generating Hypotheses for Successful Threat Hunting” (2016)

The best way to proceed with hypothesis generation is the combination of the three different types of hypotheses.

--

--

Written by Alex Teixeira

I design and build detection and SIEM/EDR/XDR content for Enterprise #SecOps teams #DetectionEngineering http://opstune.com

No responses yet

Write a response