From the course: Threat Hunting Essential Training
Unlock this course with a free trial
Join today to access over 25,500 courses taught by industry experts.
Statistical based hunting
From the course: Threat Hunting Essential Training
Statistical based hunting
- [Presenter] There is a limit to the amount of information that humans can process. However, over the years, we've developed tools to help us make sense of large amounts of data. Statistics is the discipline of collecting, analyzing, interpreting and presenting empirical data. While security professionals argue back and forth about whether these techniques are under the math, science or machine learning domains, most pros will agree that these techniques can be used to analyze and interpret big data sets. We can use the well-defined statistics discipline and a number of algorithms to help make sense of large data sets in threat hunting. Let's take a look at an example. One morning I was reading about the threat landscape, and I noticed more threat actors using Cobalt Strike than I had seen it in the past. Cobalt Strike is a commercial penetration testing software that allows an attacker to deploy an agent called a beacon…