Terminology Index

Glossary

1801 terms

Open concept maps

Showing 193-224 of 1801 terms

B
30

Behavioral Operationalization

Turning an abstract description of attacker behavior into something a threat hunter can actually search for, by defining the data sources, queries, and observable traces that the behavior would produce.

A behavior like 'credential dumping' is not directly searchable until it is operationalized into concrete artifacts, specific process activity, file access, or log events, in the data the hunter has. This translation step is what makes a hunt hypothesis executable and is central to effective, repeatable hunting.

Introduced in: Threat Hunting Fundamentals

Examples

  • Translating 'lateral movement via remote services' into specific log queries.
  • Mapping a behavior to the exact telemetry that would record it.
  • Defining observable traces for a technique before running a hunt.

No related terms linked yet.

C
2