In cybersecurity, defenders worry about threat actors and the tools and tradecraft they use, but beyond those obvious factors, a major metric we consider is the dwell time. This metric defines the time between an attacker gaining their first foothold in the target’s environment and their being discovered by the target’s security or ICT management team. Reducing the dwell time is critical focus of security investments, as the longer a threat actor is active in a target’s environment, the more damage they can do. In various reports, the average time threat actors remain in a target’s environment without detection is as much as 90 days. With the speed of digital communications meaning gigabytes of data could be removes in minutes, a dwell time of 90 days means attackers can plan, monitor, and stealthily attack their targets, covering their tracks as they go.
Sekuro’s security operations centre, using a combination of expertise, tools, and processes to detect and respond to cyber threats as fast as possible. This article looks at one of those processes, known as threat hunting, the concept of threat hunting as used by our SOC team to reduce dwell time and find indicators of attack and compromise beyond what may be possible using automated technology platforms.
Threat Hunting 101
Sekuro uses a process called threat hunting to determine whether cyber attackers (the adversary) have previously attacked your organisation or are skulking in the shadows biding their time before they strike. It sounds more glamourous than it is, as much of the work is painstakingly sifting through data looking for indicators of attack or past compromises. However, as a discipline, threat hunting is a crucial element of our defensive arsenal and serves as the basis for the additional activities the security operations centre (SOC) team undertakes outside of responding to real incidents.
This article looks at the discipline of threat hunting in the context of our SOC and explores how the incorporation of MITRE’s ATT&CK framework into the process makes it more effective than it otherwise would be.
To understand what threat hunting is, it is worth understanding what it is not. It is not the normal processes SOC teams use to build correlation rules (threat detection logic) and it’s nothing to do with incident response. Threat hunting is a process that builds on the basic functions of a SOC, using a structured approach to determining what they are looking for (the hypothesis) and the investigations they use to prove or disprove whether that target exists in the environment. This approach is typical of the scientific method, where a scientist will postulate a hypothesis then run experiments in several different ways to see if it stacks up.
As a hypothesis-based approach to threat detection, analysts seek evidence (indicators) of threats past or present, which may be direct evidence or just the by-products of something executing in the target’s environment – logs, registry changes (on Windows), configuration changes, rogue accounts and temporary files (to name a few). Some of this evidence is obvious, when you look for malware or hacking tools, but some is barely related to the primary adversarial activity, and in some cases, circumstantial at best. Threat hunting is a proactive sport suitable for only the most experienced of analysts, and sometimes leads to time consuming incident investigations, so it pays to ensure the hypothesis is sound and all avenues of investigation are explored before the SOC team pushes the panic button.
The analyst begins by building an attacker profile and theorising how that attacker would have gained access and what they may have done on the organisation’s ICT systems. This baseline of the hypothesis is then used to determine the kinds of evidence that the attacker may leave behind. Each iteration of a hypothesis drives a new cycle of investigation, where the investigator resets expectations and meticulously works through all the data, logs, systems, and artefacts available looking for indicators of compromise or indicators that an attacker is still present.
Anatomy of an ATT&CK
Sekuro adopted MITRE’s ATT&CK framework for use in our SOC and it is a fundamental tool used in all aspects of threat hunting. As a threat intelligence resource, the ATT&CK knowledge base contains all the tactics, techniques, and procedures, used by all the known Advanced Persistent Threat (APT) groups that MITRE tracks. The SOC team then uses that data to feed into hypothesis creation, then uses that information to determine what the attack may look like and what evidence may prevail.
Using the ATT&CK framework, our analysts build context-based models of a client’s business systems, then apply threat actor profiles to those models to understand where traces and post-activity artefacts are produced under certain attack (stress) conditions.
Since the focus is adversarial behaviours and how they relate to APT profiles, our SOC team can cast the net wider than a specific hypothesis and test multiple categories simultaneously using custom tools and data mining technologies. If they find any evidence or indicators that may point at a previous threat, they collaborate with the other team of SOC analysts to build new correlation rules to trigger alarms. This process of continual improvement is the core of what drives the SOC team forward, as continual improvement is the only way to keep up with the current adversarial landscape.
If you want more information on threat hunting and how it applies to your business, contact our sales team today and we will have one of our experts reach out for a chat.
