Terminology Index
Glossary
1801 terms
Showing 705-736 of 1801 terms
Frequency Analysis
A hunting and analysis technique that counts how often values occur in a dataset, so rare occurrences stand out, on the principle that unusual, infrequent activity is more likely to be malicious than common, high-volume activity.
Frequency analysis tallies occurrences, of process names, domains, user agents, parent-child pairs, so an analyst can focus on the rare 'long tail' rather than the common bulk. Attacker tooling and infrastructure are often uncommon in an environment, so low-frequency items are high-value leads. A staple of data-driven hunting and log analysis, it turns large datasets into a ranked list where outliers surface naturally for investigation.
Introduced in: Threat Hunting Fundamentals, Logging, Monitoring, and Telemetry
Examples
- Counting process names so a single rare executable stands out.
- Ranking outbound domains by frequency to spot uncommon destinations.
- Surfacing a rare parent-child process pair for investigation.
No related terms linked yet.
