Hunting Rituals #5: Why hypothesis-based threat hunting is essential in cybersecurity
ID: ae47d6b6-c086-525b-be93-7b58cb989223
STIX ID: report--ae47d6b6-c086-525b-be93-7b58cb989223
Feed Name: Group-IB Blog
This blog post describes a hypothesis-driven threat hunt that uncovered a USB-spreading malware sample which achieved persistence by creating/modifying Windows Run registry keys, copying itself to a randomly named temp executable, and overwriting iexplore.exe; the malware evaded antivirus detection. The report walks through query construction, baselining to reduce noise, process and file-creation analysis, and provides hunting queries and indicators useful for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
