Entity context turns events into investigations
An alert about an IP address is a technical fact. An alert about a named person's laptop is something you can investigate.
Context turns one into the other: whose account, what device, which department, what that system does, what it normally talks to. Without it, analysts spend most of their time assembling context by hand before they can make any judgement, which is where most of the cost in a SOC quietly goes.
More on Threat hunting
- Hunting starts with a question, not a dashboardBring a question
- Absence of evidence depends on coverageOnly the lit part was searched
- Hunts can become future detectionsLeave a bell on the path
- Threat intelligence should change a question or actionDid it move the points? Intelligence is useful when it changes what you ask or what you do
- Baseline means understanding normal variationNormal is a band, not a line
- Hunt scope should be explicitPeg out the ground first
