Cisco SecureX Threat Hunting
As advanced threats continue to proliferate throughout an organizations’ IT infrastructure, threat hunting as a practice has emerged. For an elite security organization, threat hunting takes a more proactive stance to threat detection. Threat hunting was a natural, security progression saved for the most mature environments where skilled personnel leverage knowledge and tools to formulate and investigate hypotheses relating to their organization’s security across the threat landscape. With technology advancements and automation, threat hunting is now within the reach for every organization.
Threat Hunting is an analyst-centric process enabling organizations to uncover hidden advanced threats. It takes a proactive approach to security through hypothesis-driven playbooks. Threat hunting formulates hypotheses from a variety of input variables spanning the hunter’s subject matter expertise. These hypotheses are then applied to a repeatable process and run against previously collected telemetry to find signs of compromise that have evaded detection. It produces new high-fidelity incidents escalated to the security staff for further investigation and triage.