Threat Hunting and Threat Intelligence Questions
Proactively pursuing adversaries and operationalizing knowledge of them. Covers threat hunting and hypothesis-driven investigation, threat intelligence collection and integration, indicators of compromise, the MITRE ATT&CK framework, advanced persistent threats, and situating activity within the current threat landscape. The 'go find what the alerts missed, informed by adversary knowledge' discipline.
During a complex, protracted incident you observe overlapping activity sets possibly from multiple adversary groups. Describe a method to separate activity streams, attribute actions to likely actors, prioritize containment and remediation when indicators overlap, and how to present attribution confidence and remediation prioritization to leadership without compromising ongoing evidence collection.
A sophisticated attacker uses living-off-the-land binaries (LOLBAS) and scheduled tasks to persist on endpoints and exfiltrate slowly via small periodic uploads. Draft a comprehensive threat-hunting plan: hypotheses, required telemetry, analytic detections (including anomaly baselines), containment procedures, and how you'd measure hunt success.
Design a two-week threat-hunting engagement aimed at detecting stealthy command-and-control (C2) communication that uses domain fronting and intermittent beaconing. Define hypotheses to test, telemetry sources to collect (DNS, TLS SNI, netflow, proxy logs), hunting queries or analytics to apply, and validation steps for suspected findings.
Given limited engineering resources, describe a pragmatic approach an Information Security Analyst would use to prioritize ATT&CK techniques for new detection development across the enterprise. Include at least three factors you would weigh and a simple scoring or ranking method.
Write a Sigma rule (YAML) that detects processes launching PowerShell with base64-encoded commands (i.e., contains '-EncodedCommand' or '-enc'). Include fields for title, description, detection selection, false-positive notes, and a mapping to an ATT&CK technique.
Unlock Full Question Bank
Get access to all Threat Hunting and Threat Intelligence interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.