Threat Hunting: Network Data

Threat Hunting: Network Data

1h 36mBeginner2024-01-25

Authors

Mike Wylie

Mike Wylie

Information Security Expert and Threat Manager

Course details

Despite investing resources in cybersecurity, organizations can still fall prey to cyberattacks. While properly configured technology can prevent most attacks, cybercriminals have developed techniques to evade detection. In this course, Michael Wylie, an information security expert, provides his insights, lessons learned, and advice on threat hunting using network telemetry. He discusses topics such as data sources, advantages and disadvantages of different data types, and methods for detecting malicious activity on your network.

Skills covered

Network SecurityIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Network threat hunting essentials - Staying proactive
  • The importance of network threat hunting

Thinking like the Adversary - Threat Actors

  • Threat actor types and motivations
  • Crown jewel identification

Network Data Sources

  • Network threat hunting data sources
  • Threat hunting in packets
  • Threat hunting using network flow
  • Threat hunting in infrastructure logs

Network Threat Hunting Tools

  • Use an SIEM (Security Information and Event Management) for threat-hunting
  • Use Wireshark for threat-hunting
  • Use IDS or IPS for threat-hunting
  • Use Bro or Zeek for threat-hunting
  • Security Onion

Hunting the Undetected

  • Leverage IOCs in threat hunting
  • Baseline to identify anomalies
  • Least frequency analysis to identify outliers
  • Hypothesis threat hunting

How Hackers Abuse Protocols

  • HTTP protocol attack methods
  • HTTPS protocol attack methods
  • SMB protocol attack methods
  • DNS protocol attack methods

Network Threat Hunts

  • Hunt command and control (C2)
  • Hunt lateral movement
  • Hunt remote desktop software

Conclusion

  • Continue with network threat hunting
40,000 Toman