威胁假设框架
原名:building-threat-hunt-hypothesis-framework
构建系统化威胁狩猎工作流,将情报与ATT&CK缺口转化为可验证假设,通过EDR/SIEM查询执行验证,并生成标准化报告。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-24
- TRACE 评分
- 3.4 / 5
内容概览
- When proactively hunting for indicators of building threat hunt hypothesis framework in the environment - After threat intelligence indicates active campaigns using these techniques - During incident response to scope compromise related to these techniques - When EDR or SIEM alerts trigger on related indicators - During periodic security assessments and purple team exercises - EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne) - SIEM with relevant log data ingested (Splunk, Elastic, Sentinel) - Sysmon deployed with comprehensive configuration - Windows Security Event Log forwarding enabled - Threat intelligence feeds for IOC correlation 1. Formulate Hypothesis : Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis. 2. Identify Data Sources : Determine which logs and telemetry are needed to validate or refute the hypothesis. 3. Ex…