Terminology Index
Glossary
1801 terms
Showing 193-224 of 1801 terms
B30
Behavioral Operationalization
Turning an abstract description of attacker behavior into something a threat hunter can actually search for, by defining the data sources, queries, and observable traces that the behavior would produce.
A behavior like 'credential dumping' is not directly searchable until it is operationalized into concrete artifacts, specific process activity, file access, or log events, in the data the hunter has. This translation step is what makes a hunt hypothesis executable and is central to effective, repeatable hunting.
Introduced in: Threat Hunting Fundamentals
Examples
- Translating 'lateral movement via remote services' into specific log queries.
- Mapping a behavior to the exact telemetry that would record it.
- Defining observable traces for a technique before running a hunt.
No related terms linked yet.
C2
