Terminology Index

Glossary

1801 terms

Open concept maps

Showing 513-544 of 1801 terms

D
32

Data-Driven Hunting

A threat-hunting approach that starts from the data itself, applying analytical techniques like frequency analysis, stack counting, and long-tail analysis to large datasets to surface anomalies worth investigating, rather than starting from a known threat.

Where intelligence-driven hunts start from a known actor or campaign, data-driven hunting begins with the telemetry: hunters apply statistical and analytical techniques, counting how often things occur, isolating the rare long tail, clustering, to let outliers reveal themselves. It is powerful for finding unknown threats and novel behavior, but it requires good data and analytical skill, and it complements hypothesis- and intelligence-driven hunting.

Introduced in: Threat Hunting Fundamentals, Logging, Monitoring, and Telemetry

Examples

  • Stack counting process names to spot a rare, suspicious outlier.
  • Using long-tail analysis to surface uncommon network destinations.
  • Letting frequency analysis of logins reveal anomalous activity.

No related terms linked yet.