Terminology Index

Glossary

1801 terms

Open concept maps

Showing 705-736 of 1801 terms

F
7

Frequency Analysis

A hunting and analysis technique that counts how often values occur in a dataset, so rare occurrences stand out, on the principle that unusual, infrequent activity is more likely to be malicious than common, high-volume activity.

Frequency analysis tallies occurrences, of process names, domains, user agents, parent-child pairs, so an analyst can focus on the rare 'long tail' rather than the common bulk. Attacker tooling and infrastructure are often uncommon in an environment, so low-frequency items are high-value leads. A staple of data-driven hunting and log analysis, it turns large datasets into a ranked list where outliers surface naturally for investigation.

Introduced in: Threat Hunting Fundamentals, Logging, Monitoring, and Telemetry

Examples

  • Counting process names so a single rare executable stands out.
  • Ranking outbound domains by frequency to spot uncommon destinations.
  • Surfacing a rare parent-child process pair for investigation.

No related terms linked yet.

G
25