Managed engagement / 04

Threat Hunting.

Assurance, every month, that the systems that matter are not compromised, proven with the evidence examined.

Designed and run by DFIR consultants, so the hunts start from how compromises actually unfold, and every detection is investigated with forensic techniques to a verdict: compromise, or cleared with the evidence that clears it.

Placed where a compromise would matter most, on the critical workloads and the infrastructure they depend on in IT and OT, with new hunts added when the threat or the estate changes.

3 years Minimum term, because assurance is a trend
Monthly Hunt cycle, report and debrief
DFIR Who designs and runs every hunt
IT and OT In scope, within the safety constraints agreed for OT
[ ASSURANCE, NOT VARIETY ]

Three things decide how the hunts are run.

A hunt is only as good as the person who wrote it and the depth at which its findings are followed. These three are fixed for every engagement.

A

Hunted by investigators

Hunts are designed and run by DFIR consultants. The hypotheses come from how intrusions actually progress: initial access, credential theft, lateral movement and persistence on the systems that matter.

What it changes
The questions a hunt is able to ask.
B

Every detection to a verdict

Each detection is investigated on the host with forensic techniques, through the Velociraptor agent deployed on the endpoints in scope. A lead closes as compromise or as cleared, with the evidence that decided it written down.

What it changes
Findings instead of alerts.
C

Hunted where it matters

Hunts are placed on the critical workloads, Tier 0 identity and the infrastructure they depend on. The hunt catalog changes when the threat or the estate changes, so every hunt earns its place.

What it changes
An assurance statement on the critical systems, every cycle.

Scope

Hunting where impact is highest, in IT and OT.

The hunt plan starts from the critical workloads and infrastructure, and from the techniques current detection does not cover.

Critical workloads The business applications the organization runs on, and the servers and data stores behind them.
Tier 0 identity Domain controllers, PKI, privileged identities and the cloud tenants they reach.
Where monitoring stops Threat hunting starts where security monitoring stops. Monitoring use cases are fine-tuned to be precise, so each one raises what it was written for. Hunting works through large volumes of data to find the subtle patterns that indicate malicious activity.
Gaps in detection Existing detection is mapped to MITRE ATT&CK, so hunts target the techniques current monitoring does not cover and stay clear of what the SOC already watches.
OT and industrial estates Supervisory and operations levels, historians and engineering workstations, within the safety constraints agreed for OT. Changes at the control levels go through OT change control.

How it is tooled

The tooling fits the estate. The confidence stays high.

Each engagement uses the tooling that fits the environment, and every detection is investigated to the same high level of confidence before it is called compromise or cleared.

Your SIEM and EDR The methodology is adapted to make the most of the SIEM and EDR already in place, so the hunts start from the telemetry and detection you already run.
AlexSta Velociraptor fork AlexSta's own fork of Velociraptor runs as the agent on the endpoints in scope, collecting forensic artifacts and supporting the investigation on the host.
Python and shell Python and shell scripting (bash, awk) parse and correlate the collected data for each hunt.
Network sensors Sensors capture and analyze the network traffic relevant to a hunt.
Data on premises Collected data stays in your environment. Collection, storage and analysis run on premises, with no upload to outside systems.

How a cycle runs

Five steps, repeated every month.

The survey and the coverage map are built at onboarding and kept current. The hunts, the triage and the report run every cycle.

STEP 01

Environment survey

Endpoints, servers, log sources, crown jewels and high-value accounts, refreshed whenever the estate changes.

STEP 02

Detection coverage map

Existing detection use-cases mapped to MITRE ATT&CK, to find the techniques current monitoring does not cover.

STEP 03

Hunt plan

Core hunts every month against the gaps that matter most, and intelligence-driven hunts when an active campaign targets your sector, region or technology.

STEP 04

Hunt and triage

Each hunt is a written hypothesis with the evidence it requires. Findings are triaged crown jewels and Tier 0 first, and an active compromise goes to your incident response team immediately.

STEP 05

Report and detection uplift

A monthly report and debrief, the assurance statement, an updated coverage map, and new real-time detection use-cases for your team to run.

Building the capability

Or build the function that does it.

Threat Hunting Capability Review & Enhancement reviews an existing hunting function and builds what it runs on, in five stages. It suits a SOC that will hunt with its own people.

STAGE 01

Assess

Processes, tools, data sources and integration with SOC workflows, with each gap classified as data source, automation, scope or expertise.

STAGE 02

Govern

A threat hunting charter with escalation paths and OT safety constraints, plus KPIs and a maturity roadmap.

STAGE 03

Plan

A hunt calendar and a hunt catalog drawn from your threat landscape and business context.

STAGE 04

Execute

Hunt playbooks: scope, hypothesis, ATT&CK technique, existing detection, evidence required and its quality, analytics and triage logic.

STAGE 05

Communicate

Hunt-level, weekly operational and monthly strategic reporting, with OT-specific reporting where OT is in scope.

Deliverables

Evidence every month, and detection that stays.

Every conclusion states what was examined and what it supports. Where the evidence does not settle a question, that is written down.

Monthly hunt report The hunts performed, what was found, the evidence behind each verdict, and the assurance statement for the critical systems in scope.
Detection coverage map Your monitoring mapped to MITRE ATT&CK and updated every cycle, so progress is visible technique by technique.
Real-time detection use-cases Detection content derived from the hunts, written for your own tooling and owned by your team.
Charter and playbooks From a capability engagement: the threat hunting charter and operating framework, the hunt catalog, and a playbook per hunt that someone other than its author can run.

Who this is for

Where the call usually comes from.

Assurance on critical systems Boards and CISOs who need it established, on a cycle, that the systems the organization runs on are not compromised.
OT and industrial estates Operators where a compromise has physical and safety consequences, and where hunting has to respect OT constraints.
A SOC that only sees alerts Teams with detection in place and no structured way to look for what never alerted.
A hunting function to build Organizations that want their own team to hunt, with a charter, a catalog and playbooks to run it on.

What is needed to scope it

Four answers are enough to scope it.

Environment A count of endpoints and users.
Telemetry The EDR, SIEM and network detection already in place.
OT Whether OT and ICS environments are in scope, and which levels.
Term The intended duration, with a three-year minimum for the managed service.

Scoping starts with a conversation, not a questionnaire. If hunting is the wrong instrument for the question, that is said plainly at the first call.

NEXT / RELATED SERVICE

Compromise Assessment

When the question needs one answer across the whole estate, now.

NEXT / SCOPING

Engage

Describe the situation. The call is with the consultant who would run the hunts, not a salesperson.