1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:02,790
we're going to discuss threat hunting.

3
00:00:02,790 --> 00:00:04,650
So, what is threat hunting?

4
00:00:04,650 --> 00:00:07,260
Well, threat hunting is a cybersecurity technique

5
00:00:07,260 --> 00:00:09,960
that is designed to detect the presence of threats

6
00:00:09,960 --> 00:00:11,100
that have not been discovered

7
00:00:11,100 --> 00:00:12,870
by normal security of monitoring.

8
00:00:12,870 --> 00:00:14,910
Essentially, threat hunting is the act

9
00:00:14,910 --> 00:00:16,650
of being proactive in your defense

10
00:00:16,650 --> 00:00:18,210
as opposed to being reactive

11
00:00:18,210 --> 00:00:20,820
like you are with incident response.

12
00:00:20,820 --> 00:00:22,260
When you conduct threat hunting,

13
00:00:22,260 --> 00:00:24,120
you are looking for threats within your network

14
00:00:24,120 --> 00:00:27,300
instead of waiting for them to exploit or attack you.

15
00:00:27,300 --> 00:00:29,550
Threat hunting is focused on analyzing data

16
00:00:29,550 --> 00:00:32,610
within the systems that we own and operate on a daily basis.

17
00:00:32,610 --> 00:00:33,750
To do threat hunting,

18
00:00:33,750 --> 00:00:35,850
we first need to establish a hypothesis

19
00:00:35,850 --> 00:00:37,140
by performing threat modeling

20
00:00:37,140 --> 00:00:37,973
and determining

21
00:00:37,973 --> 00:00:40,560
what potential events have the highest likelihood

22
00:00:40,560 --> 00:00:41,490
and highest impact

23
00:00:41,490 --> 00:00:43,380
if they were to occur.

24
00:00:43,380 --> 00:00:45,960
To determine this, we'll first ask the question,

25
00:00:45,960 --> 00:00:47,400
who might want to harm us?

26
00:00:47,400 --> 00:00:49,230
Who might want to break into our networks?

27
00:00:49,230 --> 00:00:51,360
And how might they be able to do that?

28
00:00:51,360 --> 00:00:53,970
We combine our threat modeling with threat intelligence

29
00:00:53,970 --> 00:00:57,000
to create a solid hypothesis about what type of campaign

30
00:00:57,000 --> 00:00:58,710
or what type of threat actor

31
00:00:58,710 --> 00:01:01,140
might want to do as harm and attack our networks.

32
00:01:01,140 --> 00:01:04,140
Then we move into profiling threat actors and activities

33
00:01:04,140 --> 00:01:05,519
by creating scenarios

34
00:01:05,519 --> 00:01:07,740
that show how a perspective attacker

35
00:01:07,740 --> 00:01:09,060
might attempt an intrusion

36
00:01:09,060 --> 00:01:11,070
and what their objectives might be.

37
00:01:11,070 --> 00:01:13,230
Here, we want to answer some basic questions

38
00:01:13,230 --> 00:01:15,570
like what TTPs might they use?

39
00:01:15,570 --> 00:01:16,770
Who wants to harm us?

40
00:01:16,770 --> 00:01:19,200
And are they insider threat, a hacktivist,

41
00:01:19,200 --> 00:01:22,080
a criminal organization, or a nation-state APT?

42
00:01:22,080 --> 00:01:23,850
Based on the answers to those questions,

43
00:01:23,850 --> 00:01:25,680
we will determine what their objectives might be

44
00:01:25,680 --> 00:01:27,870
and what systems they might be trying to get.

45
00:01:27,870 --> 00:01:30,630
At this point, we can now start our threat hunting

46
00:01:30,630 --> 00:01:31,530
on the network.

47
00:01:31,530 --> 00:01:33,690
Remember, threat hunting is going to rely

48
00:01:33,690 --> 00:01:34,740
on the use of tools

49
00:01:34,740 --> 00:01:36,660
developed for regular security monitoring

50
00:01:36,660 --> 00:01:37,740
and incident response.

51
00:01:37,740 --> 00:01:39,660
So, we're going to analyze the logs,

52
00:01:39,660 --> 00:01:41,490
look at information about our processes,

53
00:01:41,490 --> 00:01:42,360
our file systems,

54
00:01:42,360 --> 00:01:43,650
and our registry,

55
00:01:43,650 --> 00:01:45,540
including what has recently changed

56
00:01:45,540 --> 00:01:47,160
on our different hosts and servers.

57
00:01:47,160 --> 00:01:49,320
This information is usually going to be consolidated

58
00:01:49,320 --> 00:01:50,790
inside of a scene for us

59
00:01:50,790 --> 00:01:52,650
and our threat hunters will spend a lot of time

60
00:01:52,650 --> 00:01:55,230
in the security information and event management systems

61
00:01:55,230 --> 00:01:57,330
to correlate the data and analyze it.

62
00:01:57,330 --> 00:02:00,090
So, you might ask, what is different about threat hunting

63
00:02:00,090 --> 00:02:01,800
as opposed to the normal monitoring

64
00:02:01,800 --> 00:02:03,570
that your network and security operation centers

65
00:02:03,570 --> 00:02:05,160
are already performing?

66
00:02:05,160 --> 00:02:06,570
Well, the biggest difference

67
00:02:06,570 --> 00:02:07,710
is that with threat hunting,

68
00:02:07,710 --> 00:02:08,820
we begin with the assumption

69
00:02:08,820 --> 00:02:11,550
that our existing rules have failed to create an alert

70
00:02:11,550 --> 00:02:14,250
for something that may be malicious or suspicious.

71
00:02:14,250 --> 00:02:15,990
Your normal sensors do a great job

72
00:02:15,990 --> 00:02:17,880
of detecting well-known TTPs

73
00:02:17,880 --> 00:02:19,680
that already have signatures created

74
00:02:19,680 --> 00:02:21,570
and applied to our defensive systems.

75
00:02:21,570 --> 00:02:24,120
But threat hunting is looking for new things

76
00:02:24,120 --> 00:02:27,150
that may not already have signatures created for them.

77
00:02:27,150 --> 00:02:29,490
So, when we are doing threat hunting,

78
00:02:29,490 --> 00:02:32,160
we are looking for those things that aren't being detected,

79
00:02:32,160 --> 00:02:34,320
things that have bypassed the rules,

80
00:02:34,320 --> 00:02:36,690
things where the query just isn't returning the data

81
00:02:36,690 --> 00:02:37,920
that we expected.

82
00:02:37,920 --> 00:02:39,420
This is really the central premise

83
00:02:39,420 --> 00:02:42,060
that we are using when we're conducting threat hunting.

84
00:02:42,060 --> 00:02:45,270
Remember, our existing TTPs and indicators of compromise

85
00:02:45,270 --> 00:02:47,430
and our defensive systems are known because

86
00:02:47,430 --> 00:02:50,070
someone identified the bad folks doing bad things.

87
00:02:50,070 --> 00:02:52,080
But the threat actors also know

88
00:02:52,080 --> 00:02:53,790
when their TTPs are becoming well-known,

89
00:02:53,790 --> 00:02:54,630
and therefore,

90
00:02:54,630 --> 00:02:56,100
they will modify their tactics

91
00:02:56,100 --> 00:02:57,990
to try and avoid detection.

92
00:02:57,990 --> 00:03:01,470
Our goal as threat hunters is to try and detect them anyway,

93
00:03:01,470 --> 00:03:05,190
which is why we use threat hunting to find new tactics,

94
00:03:05,190 --> 00:03:06,510
techniques, and procedures

95
00:03:06,510 --> 00:03:07,590
for threat actors

96
00:03:07,590 --> 00:03:10,050
and create new indicators of compromise.

97
00:03:10,050 --> 00:03:12,090
Because of this, threat hunting is challenging

98
00:03:12,090 --> 00:03:13,410
and quite difficult to perform,

99
00:03:13,410 --> 00:03:14,940
but it's well worth it.

100
00:03:14,940 --> 00:03:16,170
To perform threat hunting,

101
00:03:16,170 --> 00:03:18,450
your analysts need to keep themselves up to date

102
00:03:18,450 --> 00:03:20,370
on the latest attacks and threats.

103
00:03:20,370 --> 00:03:23,490
To do this, they'll need to use advisories and bulletins,

104
00:03:23,490 --> 00:03:25,863
intelligence fusion and threat data.

105
00:03:26,700 --> 00:03:27,900
Advisories and bulletins

106
00:03:27,900 --> 00:03:30,030
are published by vendors and security researchers

107
00:03:30,030 --> 00:03:32,670
when new TTPs and vulnerabilities are discovered.

108
00:03:32,670 --> 00:03:34,050
When these new TTPs

109
00:03:34,050 --> 00:03:35,850
or vulnerabilities are first discovered,

110
00:03:35,850 --> 00:03:38,280
there may not be any signatures available

111
00:03:38,280 --> 00:03:39,360
in your protection suites.

112
00:03:39,360 --> 00:03:41,970
So, it is important to conduct threat hunting

113
00:03:41,970 --> 00:03:43,830
to determine if your network is at risk

114
00:03:43,830 --> 00:03:46,020
based on these bulletins and advisories.

115
00:03:46,020 --> 00:03:48,810
Threat hunters also use intelligence fusion and threat data

116
00:03:48,810 --> 00:03:49,950
in their work.

117
00:03:49,950 --> 00:03:51,480
Intelligence fusion and threat data

118
00:03:51,480 --> 00:03:54,990
involves using a SIEM and threat analysis platforms

119
00:03:54,990 --> 00:03:57,810
to efficiently identify items of concern

120
00:03:57,810 --> 00:03:59,130
within your SIEMs logs

121
00:03:59,130 --> 00:04:01,740
and the threats other security researchers

122
00:04:01,740 --> 00:04:03,990
are observing in the real world.

123
00:04:03,990 --> 00:04:05,370
These real-world threats

124
00:04:05,370 --> 00:04:09,300
are usually available as TTP or IoC threat data feeds

125
00:04:09,300 --> 00:04:11,070
that can be combined with your SIEM

126
00:04:11,070 --> 00:04:14,040
to identify suspicious activity in your own networks.

127
00:04:14,040 --> 00:04:17,310
Now, let's take a quick example of how threat hunting works.

128
00:04:17,310 --> 00:04:18,329
Pretend for a moment

129
00:04:18,329 --> 00:04:19,980
that we just received threat intelligence

130
00:04:19,980 --> 00:04:22,019
that told us that the windows desktops

131
00:04:22,019 --> 00:04:23,220
and a lot of different companies

132
00:04:23,220 --> 00:04:25,410
have been infected with a new type of malware out there

133
00:04:25,410 --> 00:04:26,400
in the wild.

134
00:04:26,400 --> 00:04:29,340
Currently, there are not any malware definitions available

135
00:04:29,340 --> 00:04:30,360
for this new threat.

136
00:04:30,360 --> 00:04:31,320
Based on the details

137
00:04:31,320 --> 00:04:33,420
that we find in the advisory or bulletin,

138
00:04:33,420 --> 00:04:35,940
we can begin threat hunting in our own network.

139
00:04:35,940 --> 00:04:38,700
For example, we might start by analyzing network traffic

140
00:04:38,700 --> 00:04:40,860
to determine if there's any outgoing traffic

141
00:04:40,860 --> 00:04:43,680
to some sort of suspicious domain or C2 server

142
00:04:43,680 --> 00:04:44,940
based on our threat research

143
00:04:44,940 --> 00:04:47,850
and looking at good reputational databases.

144
00:04:47,850 --> 00:04:49,350
Based on what we observe,

145
00:04:49,350 --> 00:04:51,420
we may create a list of different hosts

146
00:04:51,420 --> 00:04:53,400
that need to be investigated further

147
00:04:53,400 --> 00:04:55,680
because they are sending out network traffic

148
00:04:55,680 --> 00:04:57,870
to this suspicious domain.

149
00:04:57,870 --> 00:04:59,880
Then, when we look at those hosts,

150
00:04:59,880 --> 00:05:03,210
we might analyze the executable process list on those hosts,

151
00:05:03,210 --> 00:05:05,700
seeing what programs and services are being ran

152
00:05:05,700 --> 00:05:08,490
and which ones are opening that network connection.

153
00:05:08,490 --> 00:05:10,140
Then, we need to ask ourselves,

154
00:05:10,140 --> 00:05:11,310
are these valid connections

155
00:05:11,310 --> 00:05:12,870
or was this something suspicious

156
00:05:12,870 --> 00:05:14,850
that needed to be investigated further?

157
00:05:14,850 --> 00:05:15,840
If it is suspicious,

158
00:05:15,840 --> 00:05:18,600
we'll move on to analyzing other infected hosts.

159
00:05:18,600 --> 00:05:20,970
As we look at these different infected hosts,

160
00:05:20,970 --> 00:05:22,020
we can start to see

161
00:05:22,020 --> 00:05:24,030
if there's any similarities between them.

162
00:05:24,030 --> 00:05:26,580
Are they all running the same malicious processes?

163
00:05:26,580 --> 00:05:28,320
Are they all using different processes

164
00:05:28,320 --> 00:05:30,450
as a method to avoid detection?

165
00:05:30,450 --> 00:05:32,760
Finally, we can start identifying the method

166
00:05:32,760 --> 00:05:34,080
that the malicious processes

167
00:05:34,080 --> 00:05:36,330
on those different hosts actually executed.

168
00:05:36,330 --> 00:05:37,980
What allowed it to start?

169
00:05:37,980 --> 00:05:39,900
Is there a way that we can block the attack vector

170
00:05:39,900 --> 00:05:41,430
against future compromises?

171
00:05:41,430 --> 00:05:43,470
Maybe we can move to application whitelisting

172
00:05:43,470 --> 00:05:45,450
or allow listing type of system,

173
00:05:45,450 --> 00:05:47,490
or maybe we can just utilize a blacklist

174
00:05:47,490 --> 00:05:48,330
or denial list

175
00:05:48,330 --> 00:05:49,680
for the vulnerable application

176
00:05:49,680 --> 00:05:51,990
until the patch has been developed by the vendor.

177
00:05:51,990 --> 00:05:53,970
This is the idea of threat hunting

178
00:05:53,970 --> 00:05:55,710
where we take a needle in haystack

179
00:05:55,710 --> 00:05:57,120
based on the information that we have

180
00:05:57,120 --> 00:05:58,830
and try to find the attackers.

181
00:05:58,830 --> 00:06:00,780
If they made it through our automated defenses

182
00:06:00,780 --> 00:06:03,090
by using additional tactical level resources,

183
00:06:03,090 --> 00:06:04,530
we need to identify those

184
00:06:04,530 --> 00:06:06,270
so that we can build new signatures

185
00:06:06,270 --> 00:06:09,750
and add them to our IPS to block future attempts.

186
00:06:09,750 --> 00:06:11,970
Threat hunting does consume a lot of resources

187
00:06:11,970 --> 00:06:13,620
and a lot of time to conduct,

188
00:06:13,620 --> 00:06:16,050
but it provides us with a lot of benefits.

189
00:06:16,050 --> 00:06:16,883
For instance,

190
00:06:16,883 --> 00:06:18,990
threat hunting can improve your detection capabilities

191
00:06:18,990 --> 00:06:20,940
because a threat hunter finds out

192
00:06:20,940 --> 00:06:22,500
how these attackers have gotten in

193
00:06:22,500 --> 00:06:24,210
and bypass their detection suite.

194
00:06:24,210 --> 00:06:25,950
Then now, you can rewrite the rule set

195
00:06:25,950 --> 00:06:27,420
and detection algorithms

196
00:06:27,420 --> 00:06:28,890
to detect things more accurately

197
00:06:28,890 --> 00:06:30,990
and prevent future exploitation.

198
00:06:30,990 --> 00:06:33,000
So, remember, threat hunting

199
00:06:33,000 --> 00:06:35,070
often integrated into your threat intelligence

200
00:06:35,070 --> 00:06:38,370
so that we can correlate external threat intelligence fees

201
00:06:38,370 --> 00:06:40,290
with what you're seeing in your internal logs

202
00:06:40,290 --> 00:06:41,640
and other sources.

203
00:06:41,640 --> 00:06:43,110
By putting those things together,

204
00:06:43,110 --> 00:06:45,033
you now have actionable intelligence.

