Terminology Index

Glossary

1801 terms

Open concept maps

Showing 897-928 of 1801 terms

I
32

Initial Access Hunts

Threat hunts focused on finding how attackers first got in, searching for signs of phishing payloads, exploited services, or other initial-access techniques that may have established an undetected foothold.

Initial access is the entry point of an intrusion, and initial-access hunts proactively look for evidence of it: suspicious payloads from phishing, exploitation of internet-facing services, malicious logons, or rogue accounts created at entry. Forming a hypothesis about how an adversary might have gained entry in the environment, hunters search telemetry for those traces, aiming to catch a foothold the SOC's detections missed before it can be expanded.

Introduced in: Threat Hunting Fundamentals

Examples

  • Hunting for phishing payloads that may have established a foothold.
  • Searching for signs an internet-facing service was exploited for entry.
  • Looking for suspicious external logons indicating initial access.

No related terms linked yet.