Skip to main content

Threat Hunting: Origin, Evolution, and the MITRE ATT&CK Framework

N2K NetworksMarch 25, 20256 min83 views
19 connections·29 entities in this video

Defining Threat Hunting

  • 🎯 Threat hunting is the proactive process of searching through networks to detect and isolate security threats.
  • 💡 It contrasts with relying solely on security solutions to identify these threats.

Origins and Evolution of Threat Hunting

  • 🧠 The concept was initially developed by Tony Sager in the mid-2000s for the NSA as the "unifying mission model."
  • 📜 Richard Bejtlich expanded on the idea in a 2011 essay, referencing the Air Force's "hunter killer" missions.
  • ⚔️ Early concepts involved security experts actively projecting onto networks to find advanced threats.

Key Frameworks and Models

  • 🔗 In 2010, Lockheed Martin introduced the Intrusion Kill Chain, shifting focus from passive to forward-thinking defenses.
  • 💎 In 2013, the Diamond Model was published as an alternative strategic threat model.
  • 💥 Also in 2013, MITRE released the ATT&CK framework, enhancing the Kill Chain with operational intelligence and detailed adversary behaviors.

Impact of MITRE ATT&CK

  • 📚 The ATT&CK framework provides a globally accessible knowledge base of known adversary behaviors, derived from real-world observations.
  • 🛠️ It empowers threat hunters by offering a standardized database of offensive playbooks.
  • 🔍 Penetration testers can use it for red team exercises emulating known adversary behaviors.

Threat Hunting in Practice

  • 💡 John Stoner's presentation at the SANS Summit highlighted the practical application of threat hunting, referencing concepts like the Kill Chain, Diamond Model, and MITRE ATT&CK.
  • 🧠 Stoner refers to the MITRE ATT&CK framework as "brain candy" for those who may not be highly creative, providing specific techniques and tactics to guide hunting efforts.
Knowledge graph29 entities · 19 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
29 entities
Chapters3 moments

Key Moments

Transcript24 segments

Full Transcript

Topics10 themes

What’s Discussed

Threat HuntingCybersecurityNetwork SecurityMITRE ATT&CK FrameworkIntrusion Kill ChainDiamond ModelAdversary BehaviorIncident ResponseInformation AssuranceRed Teaming
Smart Objects29 · 19 links
People· 10
Companies· 4
Concepts· 8
Medias· 5
Events· 2