Image: blackhillsinfosec.com · rights & removal
Threat Hunting on the Endpoint: Hunting Adversaries Where They Live
Reporting by Black Hills Information SecurityRead the original at blackhillsinfosec.com
Executive Summary
Facts Only
* Adversaries execute code on actual systems, touching files, spawning processes, and modifying registries.
* Endpoint threat hunting seeks to find execution traces left on the host.
* Endpoint hunting provides visibility into process execution, memory access patterns, and registry modifications.
* Credential theft via Mimikatz operates in host memory and local file systems.
* Endpoint telemetry captures user and process context, such as parent processes, command-line arguments, and user identity for PowerShell execution.
* Sysmon generates logs covering process creation, network connections, file changes, and registry modifications.
* PowerShell Script Block Logging captures executed commands within PowerShell sessions.
* Windows Event Logs provide foundational telemetry.
* Velociraptor allows hunting across thousands of endpoints simultaneously.
* Wazuh centralizes the collection and analysis of endpoint telemetry.
Full Take
From the original · Black Hills Information Security
This article was originally published in the InfoSec Survival Guide: Teal Book — Threat Hunting. Read it free online HERE, or grab it on the Spearphish General Store (free digital download or a $1.25 physical copy, your call). | Here's the deal: when adversaries compromise your environment, they don't float around in abstract network flows.Read the full story at blackhillsinfosec.com
Sentinel — Human
The text reads like expert instructional writing, synthesizing established cybersecurity practices into an urgent case for endpoint visibility, making it highly probable that it was written by or heavily guided by a human expert.
