Discussion about this post

User's avatar
Allyn Roberts's avatar

Great article. We've been running ATHF since January and it's really helped improve our threat hunting process. It has helped speed up hunts and report writing, assisted with queries, tied hunts together, helped CTI flow into hunts more efficiently, and has showed us where our gaps are in the MITRE ATT&CK Framework. Still a lot more we can go to continue to improve.

Sanaika's avatar

Love this article! And agreed - as a current IR analyst I’m surrounded by CISO mythos esque talks but the operationality and actionability truly drills down to know adversarial behavior rather than trying to crystal ball zero day exploits

6 more comments...

No posts

Ready for more?