Explore
Frameworks
“When I began my journey as a SOC analyst, I was introduced to an SIEM. At that time, I had never heard of SIEMs; it was an enigma. Yet, I sat down and embarked on my SOC journey, learning from the ground up. Reflecting on my experiences, if I had to start over, I would prioritize understanding and leveraging models to navigate and comprehend complex situations more effectively. In this chapter, we will explore the significance of utilizing models in our work and how to apply them to enhance our capabilities and insights as threat hunters.”
– Roger C.B. Johnsen
Table of Contents
- Diamond Model
A practical explanation of the Diamond Model of Intrusion Analysis and how threat hunters can use it to structure observations, connect evidence and improve handover.
- Lockheed Martin Kill Chain
A practical explanation of the Lockheed Martin Cyber Kill Chain and how threat hunters can use it to reason about intrusion stages, detection opportunities and defensive disruption.
- Unified Kill Chain
A practical explanation of the Unified Kill Chain and how threat hunters can use it to map attacker progression, align observations with MITRE ATT&CK and structure investigations.
- MITRE ATT&CK
A practical explanation of MITRE ATT&CK and how threat hunters can use it as a behavioural vocabulary for hypotheses, investigations, detection coverage and reporting.
- OODA Loop
A practical explanation of the OODA Loop and how threat hunters can use it to structure observation, orientation, decision-making and action during investigations.
- Pyramid of Pain
A practical explanation of the Pyramid of Pain and how threat hunters can use it to prioritise indicators, detection logic and adversary disruption.
- Threat Hunting Frameworks
An overview of threat hunting frameworks, models and structured approaches, and how they support different parts of a mature hunting capability.
- PEAK
A practical explanation of the PEAK Threat Hunting Framework and how it can help threat hunters prepare, execute and turn hunt knowledge into lasting security improvement.
- TaHiTI
A practical explanation of TaHiTI and how it can help threat hunters turn threat intelligence into focused, risk-driven and repeatable hunting investigations.
- MaGMa
A practical explanation of MaGMa and how it can support SOC use case management, threat hunting, detection engineering and continuous improvement.
- PEAK