Exploring threat hunting frameworks

I’ve been diving deep into various threat hunting frameworks lately and wanted to know what resources you all find most helpful. For instance, the MITRE ATT&CK framework offers incredible insights, but I’m curious about tools or methodologies that have been particularly effective for you in real-world scenarios. Let’s share some best practices and strategies.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​‍​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​⁠‌​⁠​‌‍‌​‌​⁠​‌​​‍‌​⁠⁠‌‌‌‍‌⁠‍​​⁠​⁠‌⁠‌‌‌⁠‌​‌​‌​‌​⁠‍‌‍‌‌‌⁠​​‌​​⁠​‍​‍‌⁠⁠‌​

Using threat intelligence platforms like Recorded Future can really streamline the hunting process. They analyze real-world threat data, which helps prioritize what to focus on rather than going through everything manually. Have you tried incorporating any threat intelligence tools into your workflow?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌​​⁠‌⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍​⁠​‌‌‍‌⁠‌‍‍‌‌‍‌⁠‌​‌‍‌‍‍‍‌​‍‌​⁠‌​‌​‌‍​⁠‌‍‌‌‌⁠‌⁠‍‍‌⁠​​‌​‍⁠‌​‍​​‍​‍‌⁠⁠‌​

But i’ve found that integrating SIEM data with the MITRE ATT&CK framework can really enhance your threat-hunting capabilities… It helps map out known tactics and techniques to your organization’s specific alerts, making it easier to identify potential threats. Just be cautious about false positives; they can inflate your workload if you aren’t careful. @MITRE has some great resources on this too.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌​​⁠‌⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​‍​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌​‌⁠‌‌‌‌​⁠‌​‌‌​⁠​⁠​⁠‌‍⁠⁠‌​‌​‌⁠‌⁠‌‌​‍​⁠‌​‌⁠‍​​⁠‍​‌‍‌​​⁠‌⁠‌‌‌‌​‍​‍‌⁠⁠‌​