Forum Discussion
HeikeRitter
Microsoft
Mar 16, 2023Ninja Cat Giveaway: Episode 4 | Defender Experts for Hunting Overview
For this episode , your opportunity to win a plush ninja cat is the following -
Reply to this thread with:
- How would YOU explain/describe Defender Experts for Hunting to someone?
- Also in yo...
- Mar 18, 2023How would YOU explain/describe Defender Experts for Hunting to someone?
Defender Experts for Hunting is a managed threat hunting service that proactively looks for threat 24/7/365 across endpoints, Office 365, cloud applications, and identity using M365 Defender data to prioritize significant threat and help with daily SecOps work.
The following capabilities included in this managed threat hunting service:
1> DEN (Defender experts notifications) - Notifications show up as incidents in Microsoft 365 Defender, helping to improve security operations' incident response with specific information about the scope, method of entry, and remediation instructions.
2> EOD (Experts on Demand) - Click the 'Ask Defender Experts' button in M365 Defender portal to ask for help on specific incident, nation state actor, or attack vector
3> Reports - An interactive report summarizing what was hunted and found
4> Threat Hunting and Analytics -Defender Experts for Hunting look deeper to expose advanced threats and identify the scope and impact of malicious activity associated with human adversaries or hands-on-keyboard attacks.
what is Threat hunting?
Threat hunting is the proactive process of identifying and investigating potential security threats or malicious activity on a network, computer, or device. It involves analyzing system and network logs, observing user behavior patterns, and identifying anomalies and suspicious activity that indicate the presence of a threat. The aim of threat hunting is to detect security incidents before they cause harm, and to take steps to prevent them from happening again in the future.
MephistoMcT
Microsoft
Apr 04, 2023Microsoft Defender Experts for Hunting is a security service offered by Microsoft that augments a customer's existing SOC by helping them proactively hunt threats and therefore add all the expertise and threat intelligence that Microsoft and its ecosystem has to offer. This service comes both with a proactive component (like e.g. hunting and analysis) but also reactive components ("ask a Defender Expert") to enrich the SOC teams cyber security intelligence.
Threat hunting (one of the proactive services that are part of Defender Experts for Hunting) is the process of proactively searching for and identifying threats that may have evaded traditional security measures. Usually the start of a threat hunt is the search for a specific "indicator of compromise" (obtained via various threat intelligence sources) within the infrastructure that is to be protected. (e.g. on an endpoint or within the network infrastrutcure). It helps e.g. to detect "dormant / pre-implanted hooks" (e.g. implanted before a specific security monitoring solution has been implemented) before they are being actively used by the attacker and generate alarms by the relevant security systems.
Threat hunting (one of the proactive services that are part of Defender Experts for Hunting) is the process of proactively searching for and identifying threats that may have evaded traditional security measures. Usually the start of a threat hunt is the search for a specific "indicator of compromise" (obtained via various threat intelligence sources) within the infrastructure that is to be protected. (e.g. on an endpoint or within the network infrastrutcure). It helps e.g. to detect "dormant / pre-implanted hooks" (e.g. implanted before a specific security monitoring solution has been implemented) before they are being actively used by the attacker and generate alarms by the relevant security systems.