Threat Hunting
What is Threat Hunting?
The proactive process of searching through networks and datasets to detect and isolate advanced threats that evade existing security solutions. Threat hunting combines human analyst expertise with automated detection tools.
Terms that appear alongside threat hunting
Each of these is named in at least one of the same controls as threat hunting. The number is how many controls name both.
- incident response 6 shared controls
- threat intelligence 6 shared controls
- mitre 5 shared controls
- risk assessment 4 shared controls
- governance 4 shared controls
- nist 4 shared controls
- audit 4 shared controls
- authentication 4 shared controls
Frameworks that govern threat hunting
What the standards actually require on threat hunting
Requirements naming threat hunting across 6 standards, quoted from the control text.
Conduct cyber threat hunting activities to search for indicators of compromise in organizational systems and detect, track, and disrupt threats that evade existing controls.
3.11.2e · Threat Hunting →Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling;
JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage · Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA →Hunts for adversary activity introduced through the supply chain rather than waiting for an alert.
161R1-RA-10 · Threat Hunting →Requires a cyber threat hunting capability to be established and maintained to search for indicators of compromise and to detect, track and disrupt threats that have evaded existing controls, and requires that capability to be exercised at an organization-defi...
NIST800-RA-10 · Threat hunting →ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Implement detection engineering and threat hunting using ATT&CK Data Sources and detection content. Each technique includes Detection guidance + Data Sources required + analytic queries.
MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering · MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + Splunk + KQL + Yara + Snort + SIEM + Hunt →Questions people ask about threat hunting
What is Threat Hunting?
Why is Threat Hunting important for compliance?
Which compliance frameworks address Threat Hunting?
Where can I learn more about Threat Hunting?
See how Threat Hunting applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.