logo

Threat Hunting Use Case: Outbound Firewall Traffic

ID: 610247ca-7af6-5a88-a05b-a2fd38740670

STIX ID: report--610247ca-7af6-5a88-a05b-a2fd38740670

Feed Name: ReliaQuest Blog

Date Published: 2021-07-06

Date Updated: 2026-04-29

...
...

This threat-hunting playbook describes a 7–14 day use case for baselining outbound firewall traffic using application/protocol-aware firewall logs to find perimeter gaps and anomalies; it details hygiene checks (segment- and device-based baselines, policy-rule correlation) and threat-analysis techniques (rare ports/protocols, unexpected device-protocol usage, port/protocol mismatches, suspicious geolocations, high upload ratios or long sessions, excessive blocked attempts, and correlation with known-bad indicators).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.