Talk With an Expert

On The Hunt: The Retroactive and Proactive Hunt for CTI Indicators

On The Hunt: The Retroactive and Proactive Hunt for CTI Indicators (PDF, 0.54MB)Published: 29 Feb, 2024
Created by:
Dennis Basilio

Cyber threat intelligence (CTI) has many standards and models to define it. However, very few of these standards reach a technical level of implementation and instead leave it to the interpretation of organizations. Hunting for CTI indicators itself needs to be a well-defined process. Most organizations receive a list of indicators of compromise (IOCs) and conduct ad-hoc retroactive hunts for them within their environment for any historical hits. IOC hits are then proactively searched for in newly ingested data.