Tips for Effective Threat Hunting

This blog was co-written by Ramnath Venugopalan.

In May, McAfee surveyed more than 700 IT and security professionals around the world to better understand how threat hunting is used in organizations and how they hope to enhance their threat hunting capabilities. You can read the full study: Disrupting the Disruptors, Art or Science? Understanding the role of threat hunters and continuing evolution of the SOC in cybersecurity.

At the MPOWER Cybersecurity Summit, Oct. 17–19 in Las Vegas, McAfee will discuss the results of this survey and explain how our products can help customers run a next-level security operations center. We will also cover trends among threat hunters and answer questions such as:

  • What are a threat hunter’s core tools?
  • What level is your environment in the threat hunting maturity scale?
  • Do you want to improve on that scale?
  • What are top-tier SOCs doing that low-level SOCs are not?

One thing top-tier SOCs do is use six core logs to identify attacks:

  • DNS logs are one of the best sources of data within an organization. They should be compared with the various threat intelligence sources and mined for information.
  • Proxy logs are useful for exfiltration detection and forensics, identifying potential phishing attempts and suspicious domains, and identifying control server domains.
  • SMTP logs are useful but they do not necessarily capture all details due to privacy restrictions around email content. We can use them to capture header information, though not data on attachments or embedded links.
  • Windows logs can be a very rich source of data. They can also be very noisy and come in several flavors. Timeline analysis can best leverage these logs, and overlaying the other logs we describe is the key to leveraging this information. Each Windows log sheds light on a different part of the puzzle. Some of the most valuable are:
    • Authentication logs
    • Security logs
    • Application logs
    • System logs
  • DHCP logs are temporal entries that require timeline matching to correlate with log entries from other sources.
  • VPN logs are also temporal entries that require timeline matching to correlate with log entries from other sources. They are useful for detecting the theft of credentials.

Each of these logs provide insight for specific parts of the incident response process. This talk will walk through each log and identify the key insights that can be identified with specific data in that log as well as useful automation.

Are you collecting these logs? That’s only half the battle. Join us at MPOWER as we look at recent advanced persistent threats campaigns and show how these six logs can help identify breaches and create mitigations.

For more on Threat Hunting and for updates from MPOWER17, follow us on Twitter @McAfee_Labs.

Introducing McAfee+

Identity theft protection and privacy for your digital life

FacebookLinkedInTwitterEmailCopy Link

Stay Updated

Follow us to stay updated on all things McAfee and on top of the latest consumer and mobile security threats.

FacebookTwitterInstagramLinkedINYouTubeRSS

More from McAfee Labs

Back to top