威胁假设框架

原名:building-threat-hunt-hypothesis-framework

构建系统化威胁狩猎工作流,将情报与ATT&CK缺口转化为可验证假设,通过EDR/SIEM查询执行验证,并生成标准化报告。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-24
TRACE 评分
3.4 / 5

内容概览

- When proactively hunting for indicators of building threat hunt hypothesis framework in the environment - After threat intelligence indicates active campaigns using these techniques - During incident response to scope compromise related to these techniques - When EDR or SIEM alerts trigger on related indicators - During periodic security assessments and purple team exercises - EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne) - SIEM with relevant log data ingested (Splunk, Elastic, Sentinel) - Sysmon deployed with comprehensive configuration - Windows Security Event Log forwarding enabled - Threat intelligence feeds for IOC correlation 1. Formulate Hypothesis : Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis. 2. Identify Data Sources : Determine which logs and telemetry are needed to validate or refute the hypothesis. 3. Ex…

查看 SKILL 详情