Reader small image

You're reading from  Practical Threat Intelligence and Data-Driven Threat Hunting

Product typeBook
Published inFeb 2021
PublisherPackt
ISBN-139781838556372
Edition1st Edition
Right arrow
Author (1)
Valentina Costa-Gazcón
Valentina Costa-Gazcón
author image
Valentina Costa-Gazcón

Valentina Costa-Gazcón is a cyber threat intelligence analyst who specializes in tracking Advanced Persistent Threats (APTs) worldwide, using the MITRE ATT&CK Framework to analyze their tools, tactics, techniques, and procedures (TTPs). She is a self-taught developer and threat hunter with a degree in translation and interpretation from the Universidad de Málaga (UMA) and a cyber security diploma from Argentina's Universidad Tecnológica Nacional (UTN). Valentina also is one of the founders of the BlueSpace community (BlueSpaceSec) and one of the core members of Open Threat Research, founded by Roberto Rodriguez (OTR_Community).
Read more about Valentina Costa-Gazcón

Right arrow

How to determine the success of a hunting program

We mentioned some of the key points that define a successful threat hunting program in the previous chapter, Chapter 12, Understanding the Output. The definition will vary depending on the organization's mission, but it should cover at least the following:

  • The hunting team has established a data model and a data quality assurance process.
  • The hunting team drives all their hunts using threat intelligence relevant to the organization.
  • The hunting team is detecting visibility gaps too.
  • The hunting team is properly automating all generated detections.
  • The hunting team is properly documenting the hunts, successful or not.

On top of these goals, we can also assess the success of the threat hunting program depending on the threat hunting team's maturity evolution. For this, as explained in Chapter 2, What Is Threat Hunting?, you can use David Bianco's Threat Hunting Maturity Model:

...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Practical Threat Intelligence and Data-Driven Threat Hunting
Published in: Feb 2021Publisher: PacktISBN-13: 9781838556372

Author (1)

author image
Valentina Costa-Gazcón

Valentina Costa-Gazcón is a cyber threat intelligence analyst who specializes in tracking Advanced Persistent Threats (APTs) worldwide, using the MITRE ATT&CK Framework to analyze their tools, tactics, techniques, and procedures (TTPs). She is a self-taught developer and threat hunter with a degree in translation and interpretation from the Universidad de Málaga (UMA) and a cyber security diploma from Argentina's Universidad Tecnológica Nacional (UTN). Valentina also is one of the founders of the BlueSpace community (BlueSpaceSec) and one of the core members of Open Threat Research, founded by Roberto Rodriguez (OTR_Community).
Read more about Valentina Costa-Gazcón