Site navigation

Scot-Secure 2024 | How to Effectively Threat Hunt

Graham Turner

,

how to threat hunt
Speaking to a packed auditorium at DIGIT’s Scot-Secure 2024 event, Melissa Goldsmith, threat hunter and technical lead at NBCUniversal, proselytised on the the imperative need for proactive defense strategies. Namely, threat hunting.

Goldsmith’s journey into threat hunting began during her tenure at US Bank in 2020, where she made the transition from incident response to exploring the realm of threat hunting.

With a wealth of experience in red teaming, blue teaming, and threat hunting, Goldsmith is well-placed to not only note that companies always declare breaches on 4pm on a Friday, but also give some salient insight as companies poise themselves against a hostile, escalating cybersecurity environment in which, according to Goldsmith, “It’s not a question of if your company is going to be attacked and pwned. It’s a question of when and how severe.”

What is Threat Hunting?

CrowdStrike said in their 2023 threat hunting report that there is one potential intrusion every seven minutes. In the same report, they declare an intrusion as hands-on keyboard; it’s not just someone dropping malware on a system, it’s actually a human on the keyboard. The bottom line is that the earlier on in the attack lifecycle that you can find these actors in your network, the less painful, costly, and embarrassing it will be.

Achieving this through threat hunting, as described by threat hunter and technical lead at NBCUniversal, Melissa Goldsmith, is encapsulated in the mantra of “assume compromise.”

It involves actively scouring networks for anomalous activities, probing for signs of potential threats. Goldsmith emphasises the evolving nature of this pursuit, from the challenges of data overload to the complexities of adapting to new technologies like cloud and containers.

Goldsmith highlights common obstacles encountered in threat hunting, including funding constraints and the limitations of security information and event management (SIEM) systems. Additionally, she underscores the unpredictable nature of the job, where responding to emergent threats often supersedes planned activities.

For small teams venturing into threat hunting, Goldsmith stresses the importance of collaboration and knowledge sharing. Leveraging insights from colleagues in forensics, incident response, and security operations can enhance effectiveness and streamline efforts. Ultimately, a collective approach ensures that the burdens of threat hunting are shared, making the task more manageable for all involved.

Speaking on SOC analysts in particular, Goldsmith noted that “the SOC analysts are the kind of the boots on the ground, they can see all the pain points, what’s working, what’s not working, or they can start seeing some similarities like, ‘Hey, Melissa, we’re starting to see a lot of these bat loader infections. Can you maybe look into this and see if there’s anything we can do again to find them earlier on in the kill chain than what we’re currently finding them on?’ Then, the people on the right are the people that make the jobs on the left much easier.”

How to Effectively Threat Hunt 

To effectively threat hunt, there’s a few key components that join the dots: being as up-to-date as possible with your understanding of what threats are out there, especially when it comes to new technologies and complex attack surfaces such as cloud environments.

Beyond that, Goldsmith stresses the critical role of collaboration between security teams, particularly with regard to onboarding new technologies.

Goldsmith emphasises the necessity of comprehensive documentation in threat hunting, citing its importance in legal contexts and ensuring smooth knowledge transfer within security teams. From report templates to log source explanations and useful queries, detailed documentation forms the backbone of effective threat hunting operations.

On this, she said: “Documentation is your friend. This is probably coming back from the blue team side, because you never know when you might get pulled into court, that way you can say with confidence that what you’re saying is true.

“It may seem weird if you’re a team of one. Well, what happens if you start getting more people in your team or something happens to you and then somebody else has to take over your job? You want them to hit the ground running, so then they don’t have to be redoing your work.

“Some examples would be having report templates. If you’re sending out reports, who do they go to and what is the email format? Those kind of things. Explaining your log sources, because it might not just be host-based, your event logs and web logs.”


Recommended reading


Execution of a hunt, according to Goldsmith, requires a structured approach that begins with identifying hunt plans and scoping them appropriately. Leveraging diverse data sources, such as web logs and host-based logs, is crucial for gaining comprehensive visibility into network activity. Goldsmith advocates for swift escalation of potential threats to response teams, facilitating prompt investigation and mitigation.

Elucidating, Goldsmith said: “What do you want to hunt today? Say you want to look for malicious, CertUtil usage in my environment. Scope that: Do you want to focus on servers? Do you want to focus on workstations? Do you want to focus on accounting? Do you want to focus on the tech guys? Because tech people usually like to be the ones that are skirting around what they should be doing anyways.”

Measuring the success of threat hunting efforts is paramount, according to Goldsmith. She suggests metrics such as escalation rates, detection creation, and coverage of the Mitre Attack framework. By quantifying the impact of threat hunting activities, organisations can justify investments and prioritise future initiatives effectively.

Finally, continuous improvement is key, Goldsmith asserts, advocating for a proactive approach that includes automation, targeted intelligence, and collaboration with red and blue teams. Regular baselining and purple team exercises enable organisations to accurately assess their security posture and identify areas for improvement.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data