InterviewStack.io LogoInterviewStack.io

Threat Hunting and Threat Intelligence Questions

Proactively pursuing adversaries and operationalizing knowledge of them. Covers threat hunting and hypothesis-driven investigation, threat intelligence collection and integration, indicators of compromise, the MITRE ATT&CK framework, advanced persistent threats, and situating activity within the current threat landscape. The 'go find what the alerts missed, informed by adversary knowledge' discipline.

MediumTechnical
18 practiced

You discover an artifact that matches a known IoC signature but could be a legitimate system component on some hosts. Describe a validation workflow to confirm maliciousness or false positive: include hash and signature checks, parent process validation, network behavior analysis, baseline comparison, and threat intel lookup. How would you document ambiguous results?

That is every published Threat Hunting and Threat Intelligence question for Digital Forensic Examiner so far. Browse the other topics in this category, or practice this one interactively.