Threat Hunting: Origin, Evolution, and the MITRE ATT&CK Framework
N2K NetworksMarch 25, 20256 min83 views
19 connections·29 entities in this video→Defining Threat Hunting
- 🎯 Threat hunting is the proactive process of searching through networks to detect and isolate security threats.
- 💡 It contrasts with relying solely on security solutions to identify these threats.
Origins and Evolution of Threat Hunting
- 🧠 The concept was initially developed by Tony Sager in the mid-2000s for the NSA as the "unifying mission model."
- 📜 Richard Bejtlich expanded on the idea in a 2011 essay, referencing the Air Force's "hunter killer" missions.
- ⚔️ Early concepts involved security experts actively projecting onto networks to find advanced threats.
Key Frameworks and Models
- 🔗 In 2010, Lockheed Martin introduced the Intrusion Kill Chain, shifting focus from passive to forward-thinking defenses.
- 💎 In 2013, the Diamond Model was published as an alternative strategic threat model.
- 💥 Also in 2013, MITRE released the ATT&CK framework, enhancing the Kill Chain with operational intelligence and detailed adversary behaviors.
Impact of MITRE ATT&CK
- 📚 The ATT&CK framework provides a globally accessible knowledge base of known adversary behaviors, derived from real-world observations.
- 🛠️ It empowers threat hunters by offering a standardized database of offensive playbooks.
- 🔍 Penetration testers can use it for red team exercises emulating known adversary behaviors.
Threat Hunting in Practice
- 💡 John Stoner's presentation at the SANS Summit highlighted the practical application of threat hunting, referencing concepts like the Kill Chain, Diamond Model, and MITRE ATT&CK.
- 🧠 Stoner refers to the MITRE ATT&CK framework as "brain candy" for those who may not be highly creative, providing specific techniques and tactics to guide hunting efforts.
Knowledge graph29 entities · 19 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
29 entities
Chapters3 moments
Key Moments
Transcript24 segments
Full Transcript
Topics10 themes
What’s Discussed
Threat HuntingCybersecurityNetwork SecurityMITRE ATT&CK FrameworkIntrusion Kill ChainDiamond ModelAdversary BehaviorIncident ResponseInformation AssuranceRed Teaming
Smart Objects29 · 19 links
People· 10
Companies· 4
Concepts· 8
Medias· 5
Events· 2