Threat Hunting Playbook for Discovery
Objective:
Threat Hunting Playbook for Discovery

Objective:
To proactively search for and identify potential attempts by adversaries to gather information about the environment for the purpose of launching further attacks.
Hypothesis:
Adversaries have gained access to the environment and are attempting to gather information about the network, systems, and applications.
Playbook:
-
Define scope: Identify the network, endpoints, and servers that are in scope for this hunt. Ensure that the systems are up to date with the latest patches and have updated antivirus software.
-
Gather data: Collect and analyze the following data sources to identify potential reconnaissance activities:
· Endpoint logs (e.g., Windows event logs, system logs)
· Network logs (e.g., firewall logs, DNS logs)
· Application logs (e.g., web server logs, database logs)
· Anti-virus logs and reports
- Develop queries: Develop and run queries across the collected data sources to identify any suspicious activities related to reconnaissance. Queries may include:
· Any attempts to scan the network or systems
· Any attempts to gather information about the environment (e.g., domain names, system configurations)
· Any attempts to identify vulnerable systems or applications
- Analyze results: Review the results of the queries to identify potential indicators of compromise (IOCs). These may include:
· Multiple failed login attempts from the same source
· Suspicious network traffic to known command and control (C2) servers
· Unusual changes to user accounts or group membership
- Take action: Once potential IOCs have been identified, take the following actions:
· Close any open ports or services that are not needed
· Review and update firewall and access control lists to block known malicious traffic
· Conduct further investigation to confirm the existence of malicious activity
· Update antivirus signatures and firewalls to block known malicious files and hashes
· If necessary, escalate the incident to the incident response team for further action
- Report: Document the findings and actions taken during the hunt. Share the findings with the appropriate stakeholders and ensure that any necessary actions are taken to prevent future attacks.
By following this playbook, you can proactively identify potential reconnaissance activities used by adversaries and take steps to prevent further attacks on your network. It is important to conduct regular threat hunting exercises to stay ahead of potential attackers.
메타데이터
- post_id
- 7ea5b1b6e59a
- slug
- threat-hunting-playbook-for-discovery-7ea5b1b6e59a
- url
- https://medium.com/@readsecurity/threat-hunting-playbook-for-discovery-7ea5b1b6e59a
- canonical_url
- https://medium.com/@readsecurity/threat-hunting-playbook-for-discovery-7ea5b1b6e59a
- author_url
- https://medium.com/@readsecurity
- status
- ok
- fetched_at
- 2026-08-16 16:57:12