AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
How to Hunt for Persistence in a Targeted Environment
A lot of what we do from a hunting perspective is not one for one in terms of hunting detection is something to investigate. Even though the initial find was based on threat hunting even though we're collecting the same data from all these other customers we have the ability to dive into the investigation pull out some events that might be good candidates for alert based detection which we can then deploy to all managed defense customers. The feedback loop is really important once we have a finding from hunting that turned out to be interesting and we're reporting turning that into a detection that actually alerts for the sock to action quicker next time.