The Secrets of Successful Cybersecurity Threat Hunters

As cyber attacks become more complex, companies are taking a proactive approach to get ahead of hackers.

It is no news that cybersecurity attacks are becoming more sophisticated and numerous. The traditional passive approach of reacting to attacks is not being successful. While threat hunting is not a new technique, its relevance is increasing as a way to get ahead of attackers. This article provides an introduction to threat hunting and some characteristics of a successful threat hunting team.

Introduction to Threat Hunting

Threat hunting is a proactive approach to cybersecurity focused on actively searching for attackers. Threat hunters analyze the environment looking for patterns and signs of malicious activity. While human participation is critical for threat hunting, this approach also includes tools such as threat hunting systems, which can support the operation.

Threat hunters use tools to achieve highly granular visibility into the system and network. Then, they look for anomalies in the system, analyzing the possibility of a threat. Threat hunting is a systematic activity—threat hunters need to constantly look for evidence of a possible intrusion. For example, hunting for attributes such as unusual network activity or changes to registry entries.

Understanding Security Threats

Security attacks are now commonplace with data breaches appearing in the news every other day. What motivates attackers? Almost always, the primary motivation is financial gain. Attackers usually steal information they can sell on the dark web. For example, credit card numbers or medical records. Other motivations can be:

  • Political—political activists attack sites to make a political statement. For example, the hacking group Anonymous.
  • Intellectual property theft—these attacks are sometimes sponsored by nations or by rival companies seeking to gain market advantage. Attackers can steal weapons plans or commercial product designs.
  • Revenge—dissatisfied employees can wreak havoc on a company system as a way to avenge themselves. For example, leaking or misusing privileged information.
  • Fame—attackers are valued in their communities for taking down high-visibility companies. They can carry on attacks as a form of gaining recognition among other hackers.

Attackers are constantly innovating, trying new methods to gain access to systems and data. This results in an increase in cyber attacks, as evidenced by the massive data breaches reported in 2019. Here are some notable attacks:

  • Aadhaar data breach—the personal information of 1.5 billion Indian citizens was exposed in a data breach of the nation’s ID database.
  • Facebook breach—a server containing the phone numbers of 419 million users was found online. The server contained several databases, and didn’t have a password, so anybody could access it. The exposed records containing the unique Facebook ID numbers and the phone numbers linked to them.
  • Collection 1—this breach, reported by a security researcher, leaked more than one billion emails and password.
  • Fortnite data breach—early in 2019, an old unsecured website page was used to send phishing emails, exposing 200 million Fortnite user accounts.

According to the Cyber Security Breaches Survey 2019, the most common type of attacks this year were phishing, followed by ransomware and denial-of-service attacks.

The Importance of Threat Hunting Teams

Many companies continue to use passive cybersecurity measures, geared to detect intruders once they breached into the system. Attackers generally start by stealing valid login credentials. They use the stolen credentials for search-and-steal missions, using techniques that an end-user doesn’t’ use. Threat hunters look actively for these anomalies. Some of the reasons an organization should use a threat hunting team are:

  • Stealthy techniques—these days, malware easily overcome traditional cybersecurity measures. One of the stealthy techniques they use is polymorphic malware—a type of malware that continuously changes its features to avoid detection.
  • Evolving attack vectors—attackers innovate, creating new forms of attacks regularly.Threat hunting teams constantly search for new patterns and attack vectors, staying ahead of the attackers’ innovations.
  • Dwell time—the average time before detecting an attack is 180 days. Organizations cannot afford to let an attacker dwell in the system for weeks or months while the impact of the breach grows. Threat hunters can detect attackers early in the process, usually before they can cause damage, preventing dwelling time.

Threat Hunting Techniques

Threat hunters should be skilled not only in cybersecurity. They should have a broad knowledge of systems, administration, and programming, too. Below, you’ll find a number of threat-hunting techniques employed to find threats.

Searching

Threat hunters start by systematically searching data sources to find threats. This process involves using specific queries to return results. The queries shouldn’t be so broad that they return too many results or too narrow that leave out potential threats.

Some of the data sources include logs, alerts, system events or memory dumps. Threat hunters use threat hunting tools to collect and correlate the data.

Clustering

Cluster analysis is a type of Machine Learning (ML) that correlates data from distributed sources, such as logs and records from investigations. The term refers to group a set of objects in a cluster according to similarities between them. Clustering helps threat hunters to extract valuable information from terabytes of data.

The image above shows how scientists can use different algorithms to obtain different results with data.

Stack Counting

The term refers to when an investigator inspects a data set of similar values trying to find similarities. For example, when detecting an anomaly in a metric, investigators should look for clues about what is causing it. Investigators filtering the data end with a stack of data that is specific for this query. Threat hunters use filtering tools to help them with this technique.

Threat Hunting Secrets: Successful Strategies

Advanced threat hunting teams share several characteristics that contribute to their success.

Automate investigation

75% of threat hunting teams automate attack investigation. This allows the team to spend more time hunting than investigating indicators of compromise (pieces of data that identify malicious activity).

Investigating efficiently

Time is of the essence in threat hunting. The mark of a successful team is closing the investigation in 24 hours time.

Know which are your critical assets

Sometimes security teams don’t take the time to assess the assets and identify where they should prioritize their protection efforts, such as critical systems. Security teams should also identify privileged users in order to protect their credentials.

Use sandboxes to work more efficiently

A sandbox is a security mechanism that isolates running programs. This enables security teams to separate software vulnerabilities, preventing it from spreading.

Install the right tools

The basic set of tools of a threat hunting team requires a SIEM solution, endpoint monitoring, and threat intelligence. This can ensure the team can effectively detect potential threats across the network.

Know your vulnerability landscape

Your team should understand which vulnerabilities are common to your industry. This includes the potential threats and attack vectors other companies in your industry are facing.

Threat hunting workflow

Part of a successful strategy is to have an efficient workflow. Threat hunting requires you to monitor and search the network for signals of a potential attack. An efficient threat hunting workflow should include the following steps:

  • Visibility—a key component of threat hunting is identifying normal network activity. Threat hunters use monitoring tools to gain granular visibility of the environment.
  • Hypothesis—hunters search for anomalies in IPs, certificates, and activities. The goal is to try to recognize patterns that indicate malicious activity. They do this by elaborating on a hypothesis and opening an investigation to prove it.
  • Conviction—the hunters try to prove their hypothesis by searching for related indicators. This helps threat hunters to understand the characteristics and severity of the potential threat.
  • Alerting—if the potential threat is confirmed, the threat hunting team works with the incident response team to act before the threat can cause harm. Many threat hunting teams also perform remediation techniques.

The Bottom Line

Efficient threat hunting requires assessing normal network activity, installing the right tools, and following proven strategies. Threat hunters delve deep into networks, looking for patterns and signs that can indicate an attack as it occurs. As attackers become more sophisticated, a threat hunting team becomes a crucial part of any security operation, enabling security teams to effectively prevent attacks and strengthen the security posture of their organization.

Featured

  • Allegion, Comfort Technologies Implement Mobile Credentials at the Artisan Apartment Homes in Florida

    Artisan Apartment Homes, a luxury apartment complex in Dunedin, Florida, recently transitioned from mechanical keys to electronic locks and centralized system software with support from Allegion US, a leading provider of security solutions, technology and services, and Florida-based Comfort Technologies, which specializes in deploying multifamily access control, IoT devices and software management solutions. Read Now

  • Mall of America Deploys AI-Powered Analytics to Enhance Parking Intelligence

    Mall of America®, the largest shopping and entertainment complex in North America, announced an expansion of its ongoing partnership with Axis Communications to deploy cutting-edge car-counting video analytics across more than a dozen locations. With this expansion, Mall of America (MOA) has boosted operational efficiency, improved safety and security, and enabled more informed decision-making around employee scheduling and streamlining transportation for large events. Read Now

  • Security Industry Association Launches New “askSIA” AI Tool

    The Security Industry Association (SIA) has unveiled a brand-new SIA member benefit – askSIA, a conversational AI agent designed to help users get the most out of their SIA membership, easily access SIA resources and find the latest information on SIA’s training and courses, reports and publications, events, certification offerings and more. SIA members can easily find askSIA by visiting the SIA homepage or looking for the askSIA icon in the top left of webpages. Read Now

    • Industry Events
  • Industry Embraces Mobile Access, Biometrics and AI

    A combination of evolving workplace dynamics, technology innovation and new user expectations is changing how people enter and interact with physical spaces. Access control is at the heart of these changes. Combined with biometrics and AI, mobile access control has become increasingly crucial for deploying entry solutions that are seamless, secure and adaptive to user needs. Read Now

  • Sustainable Video Solution Delivered for Landmark City of London Office Development

    An advanced, end-to-end video solution from IDIS, with a focus on reducing waste and costs, has helped a major office development in the City of London align its security with sustainability objectives. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.