Threat hunting is an exercise in unpredictability. On any given day, you could be investigating ransomware attacks on schools, hospitals, or government agencies.The offenders might be entry-level attackers or full-fledged nation-states. You might be trying to piece together an attacker’s identity after the fact or called in to thwart an attack in progress. And the tactics, techniques, and procedures (TTPs) deployed across all of these scenarios may be completely different from each other, requiring equally different responses.That’s a day in the life of a threat hunter, where the only constant for security teams and managed service providers (MSPs) is to maintain constant vigilance over a client’s environment, knowing it’s just a matter of when, not if, the next attack will be coming – and trying to anticipate the “how” of the attack as best as possible. But as unpredictable as threat hunting is, there are certain guardrails and principles that MSPs can fall back on – essential pillars that make all the difference in identifying attackers and stopping them in their tracks.
When MSPs are determining their next steps for investigating a client’s environment, ejecting all traces of attacker activity, and fortifying defenses for the inevitable next attempted breach, the above should all form the backbone of any adequate response.
Guest blog courtesy of at Sophos. Read more Sophos blogs here.
1. Cleaning Out the Web of Intrusion In a Client’s Environment
No two attackers are the same, no two breaches or ransomware attacks are the same, and no two client environments are the same – each situation requires a uniquely tailored approach to thwarting an attacker, cleaning out the environment, and preventing another breach from occurring.But tailoring the approach also means working off a baseline level of corrective actions – steps that must be taken each time to ensure threat hunters are both correctly assessing the breach and flushing out attempts at another one in the future. These include:- Blocking attacker commands and C2 communications that may occur after the initial breach.
- Conducting login audits that entail disabling and removing access privileges for each compromised account on a network.
- Deploying tools like Sophos Intercept X to isolate hosts from the environment.
- Eliminating malicious processes and systems that have been left behind on compromised machines or networks, and may be used as backdoors for future attacks.
