1
1

00:00:00,720  -->  00:00:04,230
<v Instructor>Threat hunting, what is threat hunting?</v>
2

2

00:00:04,230  -->  00:00:06,870
Well, threat hunting is a cybersecurity technique
3

3

00:00:06,870  -->  00:00:09,330
that's designed to detect the presence of threats
4

4

00:00:09,330  -->  00:00:10,560
that have not been discovered
5

5

00:00:10,560  -->  00:00:12,660
by normal security monitoring.
6

6

00:00:12,660  -->  00:00:15,180
Essentially, threat hunting is proactive
7

7

00:00:15,180  -->  00:00:17,490
as opposed to being reactive like you are
8

8

00:00:17,490  -->  00:00:19,410
with an incident response.
9

9

00:00:19,410  -->  00:00:21,540
The idea here is we are going out and hunting
10

10

00:00:21,540  -->  00:00:24,420
or looking for those threats within our network
11

11

00:00:24,420  -->  00:00:26,190
instead of waiting for them to attack.
12

12

00:00:26,190  -->  00:00:28,080
Now, when you're doing a penetration test,
13

13

00:00:28,080  -->  00:00:30,000
often you're trying to break into your system
14

14

00:00:30,000  -->  00:00:31,470
to demonstrate a weakness.
15

15

00:00:31,470  -->  00:00:34,560
But with threat hunting, we are not doing that.
16

16

00:00:34,560  -->  00:00:36,600
Instead, we're trying to analyze data
17

17

00:00:36,600  -->  00:00:38,820
within the systems we already have.
18

18

00:00:38,820  -->  00:00:40,650
So, because of this threat hunting
19

19

00:00:40,650  -->  00:00:44,460
is potentially less disruptive than a penetration test.
20

20

00:00:44,460  -->  00:00:45,450
To do threat hunting,
21

21

00:00:45,450  -->  00:00:48,360
we start out by establishing a hypothesis.
22

22

00:00:48,360  -->  00:00:50,280
Now, when we establish a hypothesis,
23

23

00:00:50,280  -->  00:00:51,450
we're going to derive that
24

24

00:00:51,450  -->  00:00:53,250
from the threat modeling we've done,
25

25

00:00:53,250  -->  00:00:55,380
and it's going to be based on the potential events
26

26

00:00:55,380  -->  00:00:57,780
with higher likelihood and higher impact
27

27

00:00:57,780  -->  00:00:59,460
if they were to occur.
28

28

00:00:59,460  -->  00:01:01,350
So essentially, we're going to sit around
29

29

00:01:01,350  -->  00:01:03,937
and we're going to think, "Who might want to harm us?"
30

30

00:01:03,937  -->  00:01:05,610
"Who might want to break into our networks,
31

31

00:01:05,610  -->  00:01:07,620
and how might they be able to do that?"
32

32

00:01:07,620  -->  00:01:09,660
And by going through our threat intelligence,
33

33

00:01:09,660  -->  00:01:11,970
we can create a good hypothesis
34

34

00:01:11,970  -->  00:01:13,590
about what type of campaign
35

35

00:01:13,590  -->  00:01:16,680
or what type of adversary group might want to do us harm.
36

36

00:01:16,680  -->  00:01:17,610
Then, we're going to move
37

37

00:01:17,610  -->  00:01:20,550
into profiling threat actors and activities.
38

38

00:01:20,550  -->  00:01:22,230
At this point, we're really going to be relying
39

39

00:01:22,230  -->  00:01:24,120
on that threat intelligence.
40

40

00:01:24,120  -->  00:01:26,010
We're going to start creating scenarios
41

41

00:01:26,010  -->  00:01:28,260
that show how a prospective attacker
42

42

00:01:28,260  -->  00:01:29,700
might attempt an intrusion
43

43

00:01:29,700  -->  00:01:32,190
and what their objectives might be.
44

44

00:01:32,190  -->  00:01:34,387
Again, we're going to sit back and think to ourself,
45

45

00:01:34,387  -->  00:01:36,877
"What TTPs might they use?"
46

46

00:01:36,877  -->  00:01:38,167
"Who wants to harm us?"
47

47

00:01:38,167  -->  00:01:40,230
"Are they an insider, a hacktivist,
48

48

00:01:40,230  -->  00:01:41,613
a nation state, or an APT?
49

49

00:01:42,540  -->  00:01:43,800
And based on that,
50

50

00:01:43,800  -->  00:01:45,510
we are going to start determining
51

51

00:01:45,510  -->  00:01:47,340
what their objectives might be
52

52

00:01:47,340  -->  00:01:49,743
and what systems they might be going after.
53

53

00:01:50,610  -->  00:01:53,160
At that point, we're going to start our threat hunting
54

54

00:01:53,160  -->  00:01:55,590
and we're going to use different tactics to do this.
55

55

00:01:55,590  -->  00:01:57,750
Now remember, threat hunting is going to rely
56

56

00:01:57,750  -->  00:01:59,160
on the use of tools developed
57

57

00:01:59,160  -->  00:02:02,430
for regular security monitoring and instant response.
58

58

00:02:02,430  -->  00:02:05,250
We're going to be analyzing logs, process information,
59

59

00:02:05,250  -->  00:02:07,170
and file system, and registry changes
60

60

00:02:07,170  -->  00:02:08,700
from all the different hosts.
61

61

00:02:08,700  -->  00:02:10,530
Generally, all that information
62

62

00:02:10,530  -->  00:02:13,320
is going to be consolidated for us inside of a SIEM.
63

63

00:02:13,320  -->  00:02:15,360
By being inside of a security information
64

64

00:02:15,360  -->  00:02:16,890
and event management system,
65

65

00:02:16,890  -->  00:02:19,110
we're going to be able to correlate that data quicker
66

66

00:02:19,110  -->  00:02:21,030
and do better threat hunting instead of having to go
67

67

00:02:21,030  -->  00:02:23,100
to each of those systems individually.
68

68

00:02:23,100  -->  00:02:25,230
Now, one of the keys to remember with threat hunting
69

69

00:02:25,230  -->  00:02:26,640
is that we have to assume
70

70

00:02:26,640  -->  00:02:28,740
that the existing rules have failed
71

71

00:02:28,740  -->  00:02:29,940
when we're threat hunting.
72

72

00:02:29,940  -->  00:02:31,440
And what I mean by that is
73

73

00:02:31,440  -->  00:02:33,690
you already have monitoring systems in place
74

74

00:02:33,690  -->  00:02:35,550
that are detecting and monitoring things
75

75

00:02:35,550  -->  00:02:37,020
across your networks,
76

76

00:02:37,020  -->  00:02:38,730
and if they were working properly,
77

77

00:02:38,730  -->  00:02:40,860
you'd already have found this bad guy.
78

78

00:02:40,860  -->  00:02:42,420
So, when we're doing threat hunting,
79

79

00:02:42,420  -->  00:02:44,940
we're looking for those things that aren't detected,
80

80

00:02:44,940  -->  00:02:46,860
things that have bypassed the rules,
81

81

00:02:46,860  -->  00:02:48,420
things where the query isn't returning
82

82

00:02:48,420  -->  00:02:49,920
the data we expected it to,
83

83

00:02:49,920  -->  00:02:52,920
and that is really the crux of doing threat hunting.
84

84

00:02:52,920  -->  00:02:55,350
These tactics are developed around an awareness
85

85

00:02:55,350  -->  00:02:57,180
that the adversary is smart
86

86

00:02:57,180  -->  00:03:00,120
and they have good TTPs to try to to avoid detection,
87

87

00:03:00,120  -->  00:03:03,510
and now we're going out and trying to detect them anyway.
88

88

00:03:03,510  -->  00:03:05,100
So that's the thing you have to remember
89

89

00:03:05,100  -->  00:03:06,300
when you're doing threat hunting
90

90

00:03:06,300  -->  00:03:09,240
is that it is challenging and it is very difficult,
91

91

00:03:09,240  -->  00:03:11,310
but it is worth it.
92

92

00:03:11,310  -->  00:03:13,230
Let's take a quick example here.
93

93

00:03:13,230  -->  00:03:14,970
Let's say that we had threat intelligence
94

94

00:03:14,970  -->  00:03:16,620
that told us that Windows desktops
95

95

00:03:16,620  -->  00:03:18,810
in a lot of different companies have been infected
96

96

00:03:18,810  -->  00:03:20,850
with a new type of malware that's out there
97

97

00:03:20,850  -->  00:03:23,940
and there's not any current malware definitions for it.
98

98

00:03:23,940  -->  00:03:25,680
Well, we can start threat hunting
99

99

00:03:25,680  -->  00:03:27,600
based on that threat information.
100

100

00:03:27,600  -->  00:03:28,830
What might we do?
101

101

00:03:28,830  -->  00:03:31,170
We might start with analyzing network traffic
102

102

00:03:31,170  -->  00:03:33,390
to determine if there's any outgoing traffic
103

103

00:03:33,390  -->  00:03:35,400
to some sort of a suspicious domain
104

104

00:03:35,400  -->  00:03:36,900
or some kind of a C2 server
105

105

00:03:36,900  -->  00:03:39,540
based on our threat research and reputational databases
106

106

00:03:39,540  -->  00:03:41,370
that we talked about previously.
107

107

00:03:41,370  -->  00:03:42,990
This will give us a list of different hosts
108

108

00:03:42,990  -->  00:03:44,700
that we might want to investigate further
109

109

00:03:44,700  -->  00:03:47,160
because they're the ones sending that traffic there.
110

110

00:03:47,160  -->  00:03:48,630
Then when we look at those hosts,,
111

111

00:03:48,630  -->  00:03:52,200
we might analyze the executable process list on those hosts,
112

112

00:03:52,200  -->  00:03:54,600
seeing what programs and services are being run
113

113

00:03:54,600  -->  00:03:56,970
and which ones were opening that network connection.
114

114

00:03:56,970  -->  00:03:58,380
Were these valid connections
115

115

00:03:58,380  -->  00:04:00,450
or was this something that's suspicious
116

116

00:04:00,450  -->  00:04:02,340
that needs to be investigated further?
117

117

00:04:02,340  -->  00:04:03,840
If it is, we're going to move on
118

118

00:04:03,840  -->  00:04:05,670
to analyzing other infected hosts.
119

119

00:04:05,670  -->  00:04:08,100
And as we look at all these different infected hosts,
120

120

00:04:08,100  -->  00:04:08,933
we can start to see
121

121

00:04:08,933  -->  00:04:10,830
if there's any similarities between them.
122

122

00:04:10,830  -->  00:04:13,170
Are they all running the same malicious process,
123

123

00:04:13,170  -->  00:04:16,290
or are they using different things to avoid detection?
124

124

00:04:16,290  -->  00:04:18,960
And then finally, we might start identifying the method
125

125

00:04:18,960  -->  00:04:20,250
that that malicious process
126

126

00:04:20,250  -->  00:04:22,890
on those different hosts was actually executed.
127

127

00:04:22,890  -->  00:04:24,510
What allowed it to start up?
128

128

00:04:24,510  -->  00:04:26,400
Is there a way we can block that attack vector
129

129

00:04:26,400  -->  00:04:27,960
against future compromises?
130

130

00:04:27,960  -->  00:04:29,730
Maybe we can move to a whitelisting system
131

131

00:04:29,730  -->  00:04:32,310
or we can blacklist that vulnerable application
132

132

00:04:32,310  -->  00:04:34,230
until a patch has been developed.
133

133

00:04:34,230  -->  00:04:35,940
All of these are things that we can think about
134

134

00:04:35,940  -->  00:04:38,010
as we go through and do threat hunting.
135

135

00:04:38,010  -->  00:04:39,390
And so that's the idea of threat hunting
136

136

00:04:39,390  -->  00:04:41,190
is we take this needle in a haystack
137

137

00:04:41,190  -->  00:04:43,050
based on the information we have
138

138

00:04:43,050  -->  00:04:44,880
and how we can better protect our systems
139

139

00:04:44,880  -->  00:04:46,410
and try to find the bad guy
140

140

00:04:46,410  -->  00:04:48,990
if they made it in through our automated defenses
141

141

00:04:48,990  -->  00:04:52,230
by using additional tactical level resources.
142

142

00:04:52,230  -->  00:04:53,220
Now, one of the big things
143

143

00:04:53,220  -->  00:04:54,480
you have to remember with threat hunting is
144

144

00:04:54,480  -->  00:04:56,640
it does consume a lot of resources
145

145

00:04:56,640  -->  00:04:58,740
and a lot of time for you to conduct it,
146

146

00:04:58,740  -->  00:05:01,920
but it can give you a lot of great benefits.
147

147

00:05:01,920  -->  00:05:03,540
For instance, it can help you
148

148

00:05:03,540  -->  00:05:05,670
to improve your detection capabilities
149

149

00:05:05,670  -->  00:05:07,560
because when a threat hunter finds a way
150

150

00:05:07,560  -->  00:05:09,030
that these bad guys have gotten in
151

151

00:05:09,030  -->  00:05:10,830
and bypassed your detection,
152

152

00:05:10,830  -->  00:05:13,470
you can then feed that back into the detection plan
153

153

00:05:13,470  -->  00:05:15,180
so you can rewrite the rule sets,
154

154

00:05:15,180  -->  00:05:17,190
you can rewrite the detection algorithms,
155

155

00:05:17,190  -->  00:05:18,210
and you can make sure that you use
156

156

00:05:18,210  -->  00:05:20,250
additional scripting and customizations
157

157

00:05:20,250  -->  00:05:22,740
to detect things more accurately.
158

158

00:05:22,740  -->  00:05:24,720
This way, your results from threat hunting
159

159

00:05:24,720  -->  00:05:27,180
can be used to improve your signature-based detection
160

160

00:05:27,180  -->  00:05:29,130
and prevent future infections.
161

161

00:05:29,130  -->  00:05:30,360
Another thing you can do
162

162

00:05:30,360  -->  00:05:32,670
is it can be integrated with your intelligence.
163

163

00:05:32,670  -->  00:05:35,430
Threat hunting is a great use case for correlating
164

164

00:05:35,430  -->  00:05:37,590
that external threat intelligence you've been getting
165

165

00:05:37,590  -->  00:05:38,490
with what you're seeing
166

166

00:05:38,490  -->  00:05:40,740
in your internal logs and other sources.
167

167

00:05:40,740  -->  00:05:42,360
By putting those two things together,
168

168

00:05:42,360  -->  00:05:44,940
you now have actionable intelligence.
169

169

00:05:44,940  -->  00:05:46,380
The third benefit you can get
170

170

00:05:46,380  -->  00:05:48,810
is to reduce your attack surface area.
171

171

00:05:48,810  -->  00:05:51,360
The benefit here is as you're doing your threat hunting,
172

172

00:05:51,360  -->  00:05:54,030
you're able to identify the entire attack surface
173

173

00:05:54,030  -->  00:05:57,240
and where a bad guy may have gotten into your network.
174

174

00:05:57,240  -->  00:05:58,710
Based on that, you can go back
175

175

00:05:58,710  -->  00:06:00,600
and reduce that attack surface.
176

176

00:06:00,600  -->  00:06:03,300
This also can help you lock attack vectors
177

177

00:06:03,300  -->  00:06:04,740
because you're now understanding
178

178

00:06:04,740  -->  00:06:06,660
the different attack vectors that are being used
179

179

00:06:06,660  -->  00:06:09,480
and the different TTPs by that bad guy
180

180

00:06:09,480  -->  00:06:11,700
and you can then add additional security controls
181

181

00:06:11,700  -->  00:06:14,430
to try to block those different ports or interfaces
182

182

00:06:14,430  -->  00:06:16,590
and prevent them from getting into your network.
183

183

00:06:16,590  -->  00:06:18,300
And finally, it's going to help you
184

184

00:06:18,300  -->  00:06:20,610
to identify critical assets.
185

185

00:06:20,610  -->  00:06:21,570
This is really important
186

186

00:06:21,570  -->  00:06:23,310
because as you're doing your threat hunting,
187

187

00:06:23,310  -->  00:06:24,420
you're going to start seeing
188

188

00:06:24,420  -->  00:06:26,880
what things people tend to go after
189

189

00:06:26,880  -->  00:06:28,470
and you're going to end up figuring out
190

190

00:06:28,470  -->  00:06:29,940
what are the best defensive options
191

191

00:06:29,940  -->  00:06:32,850
for those critical systems and data assets.
192

192

00:06:32,850  -->  00:06:33,930
One of the things we tend to do
193

193

00:06:33,930  -->  00:06:35,880
is we will bundle those assets together
194

194

00:06:35,880  -->  00:06:37,800
with a certain layer of security controls
195

195

00:06:37,800  -->  00:06:40,740
around those important assets to improve the monitoring
196

196

00:06:40,740  -->  00:06:43,770
and prevention capabilities around them even further
197

197

00:06:43,770  -->  00:06:45,150
because we see that adversaries
198

198

00:06:45,150  -->  00:06:47,070
are continually going after those targets,
199

199

00:06:47,070  -->  00:06:48,930
we want to make them an even harder target
200

200

00:06:48,930  -->  00:06:50,430
for the adversary to get into.
