Terminology Index
Glossary
1801 terms
Showing 897-928 of 1801 terms
Initial Access Hunts
Threat hunts focused on finding how attackers first got in, searching for signs of phishing payloads, exploited services, or other initial-access techniques that may have established an undetected foothold.
Initial access is the entry point of an intrusion, and initial-access hunts proactively look for evidence of it: suspicious payloads from phishing, exploitation of internet-facing services, malicious logons, or rogue accounts created at entry. Forming a hypothesis about how an adversary might have gained entry in the environment, hunters search telemetry for those traces, aiming to catch a foothold the SOC's detections missed before it can be expanded.
Introduced in: Threat Hunting Fundamentals
Examples
- Hunting for phishing payloads that may have established a foothold.
- Searching for signs an internet-facing service was exploited for entry.
- Looking for suspicious external logons indicating initial access.
No related terms linked yet.
