
Attack-Based Hunting focuses on identifying specific cyberattacks by analyzing evidence that might not be detectable through conventional security mechanisms. This methodology is ideal for beginners as it requires foundational knowledge of specific attacks rather than broad cybersecurity experience.
The workflow of Attack-Based Hunting begins with targeted questions aimed at uncovering specific threats within your network.
It starts by asking questions like "Has _________ happened on my network?" Examples include:
Scenario: Credential theft often involves the use of unauthorized applications to dump credentials from system memory, leading to unauthorized access.
💡 Note: In our lab exercise, we will follow this Attack-Based Hunting methodology to identify and investigate each question. We will apply the questions and techniques described above to gather evidence, analyze the data, and understand the nature of the threats to answer each question. This hands-on application will help solidify your understanding and enable you to apply these strategies in real-world scenarios effectively.
