Threat Hunting Use Case: Outbound Firewall Traffic
ID: 610247ca-7af6-5a88-a05b-a2fd38740670
STIX ID: report--610247ca-7af6-5a88-a05b-a2fd38740670
Feed Name: ReliaQuest Blog
This threat-hunting playbook describes a 7–14 day use case for baselining outbound firewall traffic using application/protocol-aware firewall logs to find perimeter gaps and anomalies; it details hygiene checks (segment- and device-based baselines, policy-rule correlation) and threat-analysis techniques (rare ports/protocols, unexpected device-protocol usage, port/protocol mismatches, suspicious geolocations, high upload ratios or long sessions, excessive blocked attempts, and correlation with known-bad indicators).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
