Prepare Equipment and Team Procedures
Excerpt from "Hunt Methodology" By Christian B.
Introduction
The process of updating your analyst workstations and sensor platforms is just as important as ensuring that the network you are defending is secure. Understand that once you integrate your tools into the network, your tools are now an additional attack vector on that network. As discussed under Indicator of Compromise (IOC), it is also important during this time to ensure that all necessary IOCs are included in your sensor dashboards to ease the hunting process.
Team procedures include the hunting process, identifying roles within the team (host analyst, network analyst, etc.), and laying out the reporting process for the team.
Last updated