{"id":1570,"date":"2017-09-12T20:17:32","date_gmt":"2017-09-12T19:17:32","guid":{"rendered":"http:\/\/www.halkynconsulting.co.uk\/a\/?p=1570"},"modified":"2017-09-12T20:17:32","modified_gmt":"2017-09-12T19:17:32","slug":"threat-hunting-essential-every-business","status":"publish","type":"post","link":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/","title":{"rendered":"Threat Hunting &#8211; essential for every business"},"content":{"rendered":"<figure id=\"attachment_1571\" aria-describedby=\"caption-attachment-1571\" style=\"width: 300px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1571\" data-permalink=\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/equifax_threat_hunting\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?fit=2708%2C1464&amp;ssl=1\" data-orig-size=\"2708,1464\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Equifax &#8211; Needed good threat hunting\" data-image-description=\"&lt;p&gt;Equifax &#8211; Needed good threat hunting&lt;\/p&gt;\n\" data-image-caption=\"&lt;p&gt;Equifax &#8211; Needed good threat hunting&lt;\/p&gt;\n\" data-medium-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?fit=300%2C162&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?fit=1024%2C554&amp;ssl=1\" class=\"size-medium wp-image-1571\" src=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?resize=300%2C162&#038;ssl=1\" alt=\"Equifax - Needed good threat hunting\" width=\"300\" height=\"162\" srcset=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?resize=300%2C162&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?resize=768%2C415&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?resize=1024%2C554&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/equifax_Threat_hunting.png?w=2400&amp;ssl=1 2400w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><figcaption id=\"caption-attachment-1571\" class=\"wp-caption-text\">Equifax &#8211; Needed good threat hunting<\/figcaption><\/figure>\n<p>Lots of articles, blog posts and webcasts talk about threat hunting. Despite this few, if any, organisations do it. This is a mistake.<\/p>\n<p>Security hit the headlines again recently, when <a href=\"https:\/\/krebsonsecurity.com\/2017\/09\/the-equifax-breach-what-you-should-know\/\">Equifax admitted to a breach<\/a> exposing around 143 million records of personal data. While details are still emerging, it looks like the attackers compromised an external website and exfiltrated the data. There are no specifics on the attack yet but it takes time to copy out that much data<a href=\"#one\"><sup>1<\/sup><\/a>. Good threat hunting uses this time to detect attackers. This would have allowed Equifax to implement countermeasures to minimise the breach<a href=\"http:\/\/two\"><sup>2<\/sup><\/a>.<\/p>\n<p>Any organisation can threat hunt. Threat hunting uses your existing security controls to identify attackers before they can destroy your business. It doesn&#8217;t replace anything. You cant use it to replace your AV or firewalls, no matter what vendors say. Hunting doesn&#8217;t mean you can get rid of your incident response teams.<\/p>\n<p>In our experience, effective threat hunting simply makes everything else work better. The hunts give your IR teams better data to work from. Lessons you learn from hunting helps establish more effective controls. \u00a0In short, good threat hunting makes everything better.<\/p>\n<p>Every organisation should hunt threats on their network. You don&#8217;t need to buy anything new and you can do it with your own staff. This post gives some tips to get you started but nothing beats experience and formal training. Halkyn Security offer a threat hunting service, which includes helping set up your teams to hunt. However if you want formal training we strongly recommend <a href=\"https:\/\/www.sans.org\/\">SANS<\/a> courses, at least for key staff.<\/p>\n<h2>Cyber Security and Threat Hunting<\/h2>\n<p>Traditional security focuses on established controls. This is your firewall, endpoint antivirus, mail filter and similar tools. A very good example of traditional security is the <a href=\"http:\/\/www.halkynconsulting.co.uk\/a\/?s=cyber+essentials\">Cyber Essentials<\/a> scheme. As the name says, this is essential.<\/p>\n<p>Next you need to ensure a way to respond to incidents. From Talk Talk to Equifax, it is apparent that incidents will continue to happen. As a result,\u00a0<a href=\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/03\/security-incident-response-matters\/\">incident response really does matter<\/a>.<\/p>\n<p>Even with this in place, problems will still happen. Advanced Persistent Threat might be a marketing term, but the reality is persistent attackers exist. Criminals, or nation states, will spend time subverting your controls.<\/p>\n<p>Here lies the problem. If an attacker can bypass your controls, what triggers your incident response process? Often, sadly, it is public notification when other people discover your breach.<\/p>\n<figure id=\"attachment_1591\" aria-describedby=\"caption-attachment-1591\" style=\"width: 123px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1591\" data-permalink=\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/threathunting-equation\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/threathunting-equation.png?fit=123%2C19&amp;ssl=1\" data-orig-size=\"123,19\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Threat Hunting &#8211; The IR Equation\" data-image-description=\"&lt;p&gt;Threat Hunting &#8211; The IR Equation&lt;\/p&gt;\n\" data-image-caption=\"&lt;p&gt;Threat Hunting &#8211; The IR Equation&lt;\/p&gt;\n\" data-medium-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/threathunting-equation.png?fit=123%2C19&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/threathunting-equation.png?fit=123%2C19&amp;ssl=1\" class=\"wp-image-1591 size-full\" src=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/threathunting-equation.png?resize=123%2C19&#038;ssl=1\" alt=\"Threat Hunting - The IR Equation\" width=\"123\" height=\"19\" data-recalc-dims=\"1\" \/><figcaption id=\"caption-attachment-1591\" class=\"wp-caption-text\">Threat Hunting &#8211; The IR Equation<\/figcaption><\/figure>\n<p>Defending your information relies on a simple equation. If the time to detect (D) the attackers and the time to respond (R) to the attack is less than it takes the attacker (A) to complete their mission, you win. If it isn&#8217;t, the attacker wins. The fundamental goal of threat hunting is to speed up your side. This is how you win.<\/p>\n<p>When the dust settles, it turns out most breaches last months. Attackers spend time moving around. They collect sensitive data. The data is hoarded into staging servers. Eventually, the attackers exfiltrate the data. At this point it is too late for anything other than a PR exercise to limit the damage. However, in the weeks and months before this your organisation has thousands of opportunities to detect and defeat the attack. Threat hunting really does make the difference.<\/p>\n<h2>Threat hunting for beginners<\/h2>\n<p>You agree threat hunting is a good idea, now where do you start? This guide can help but remember nothing matches either skilled staff or bringing in dedicated threat hunting teams.<\/p>\n<p>To get started, think of each threat hunt as a way of testing a theory. Build a theory. Decide what evidence would support it (or disprove it) and then collect the data.<\/p>\n<p>Every environment is different so we cant give you a specific examples for your network here. However, we can provide some examples you might want to tailor:<\/p>\n<h3>Threat hunting example scenarios<\/h3>\n<p>Here are some example threat hunting scenarios. This is not an exhaustive list and the idea is you will build on this to develop good practices for your own organisation.<\/p>\n<p><strong>Network Threats<\/strong><\/p>\n<ul>\n<li><span style=\"text-decoration: underline;\">Command and Control Channels<\/span>. If you have a compromised device, it has to talk to the attackers. Collate your firewall and proxy logs. Split them into hourly segments. Find any device which is present in every segment. Establish why.<\/li>\n<li><span style=\"text-decoration: underline;\">Unusual protocols<\/span>. Check the data going out of your organisation. If you see encrypted traffic on port 80 it is unusual. Establish what has caused this.<\/li>\n<li><span style=\"text-decoration: underline;\">Suspicious encryption<\/span>. When your users visit HTTPS sites, there is a TLS\/SSL handshake. When malware calls home it normally uses preset encryption. Look at your Port 443 traffic and investigate any connections without a handshake.<\/li>\n<\/ul>\n<p><strong>Endpoint Threats<\/strong><\/p>\n<ul>\n<li><span style=\"text-decoration: underline;\">Persistence<\/span>. Collate startup entries (registry keys, autoruns etc) from all endpoints and scan for unusual entries. Any machine with unique software in startup \/ run keys should be investigated.<\/li>\n<li><span style=\"text-decoration: underline;\">Account use<\/span>. Collate event logs from all endpoints and scan for user account logins. Investigate outliers and unusual events like remote logins with local accounts.<\/li>\n<li><span style=\"text-decoration: underline;\">Unusual software<\/span>. Audit the software installed on all your devices. Sort the list to identify what software is only on one or two devices. Investigate this software.<\/li>\n<\/ul>\n<h2>Threat Hunting &#8211; the future<\/h2>\n<p>As we said, this is just the start. Run some hunts with the information here and see what happens. If you find attackers, roll into your incident response. When it comes to the lessons learned feed back into your future threat hunting. As you mature, you can integrate threat intelligence feeds.<\/p>\n<p>If you aren&#8217;t sure where to begin, consider sending your staff on training courses or <a href=\"http:\/\/www.halkynconsulting.co.uk\/contact\/contact-security-team\">bringing in external help<\/a>.<\/p>\n<p>The more you hunt, the better you will get and the more you will learn. The time to start is right now.<\/p>\n<hr \/>\n<p><a id=\"one\"><\/a>1 &#8211; If each record was 1kb in size, this is a 143gb data set for the attackers to exfiltrate without detection.<\/p>\n<p><a id=\"two\"><\/a>2 &#8211; We have no way of knowing if Equifax was running threat hunts or had other controls in place. This is not a dissection of their specific situation, it is just an example.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lots of articles, blog posts and webcasts talk about threat hunting. Despite this few, if any, organisations do it. This is a mistake. Security hit the headlines again recently, when Equifax admitted to a breach exposing around 143 million records of personal data. While details are still emerging, it looks like the attackers compromised an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1572,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[5],"tags":[159,6,140,158],"class_list":["post-1570","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyber-security","tag-infosec","tag-security","tag-threat-hunting","entry","has-media"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Threat Hunting - essential for every business - Halkyn Security Blog<\/title>\n<meta name=\"description\" content=\"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat Hunting - essential for every business - Halkyn Security Blog\" \/>\n<meta property=\"og:description\" content=\"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\" \/>\n<meta property=\"og:site_name\" content=\"Halkyn Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2017-09-12T19:17:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/ThreatHunting_PewPew.png?fit=1996%2C1261&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"1996\" \/>\n\t<meta property=\"og:image:height\" content=\"1261\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Halkyn Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:site\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Halkyn Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#article\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\"},\"author\":{\"name\":\"Halkyn Security\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/3cfcd2267f12bbcce6a10159022c3df2\"},\"headline\":\"Threat Hunting &#8211; essential for every business\",\"datePublished\":\"2017-09-12T19:17:32+00:00\",\"dateModified\":\"2017-09-12T19:17:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\"},\"wordCount\":1041,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"keywords\":[\"Cyber Security\",\"Information Security\",\"Security\",\"Threat Hunting\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\",\"name\":\"Threat Hunting - essential for every business - Halkyn Security Blog\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\"},\"datePublished\":\"2017-09-12T19:17:32+00:00\",\"dateModified\":\"2017-09-12T19:17:32+00:00\",\"description\":\"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.\",\"breadcrumb\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Halkyn Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Threat Hunting &#8211; essential for every business\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"name\":\"Halkyn Security Blog\",\"description\":\"Specialist Security &amp; Risk Management Consultants\",\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\",\"name\":\"Halkyn Consulting\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"contentUrl\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"width\":\"990\",\"height\":\"170\",\"caption\":\"Halkyn Consulting\"},\"image\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/2329571\",\"https:\/\/twitter.com\/HalkynSecurity\"]},{\"@type\":\"Person\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/3cfcd2267f12bbcce6a10159022c3df2\",\"name\":\"Halkyn Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4126abc936773e5e8bd38e030d54306e161190a7d6166dba7edadb6caf13b504?s=96&d=retro&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4126abc936773e5e8bd38e030d54306e161190a7d6166dba7edadb6caf13b504?s=96&d=retro&r=g\",\"caption\":\"Halkyn Security\"},\"description\":\"Halkyn Security Consultants.\",\"sameAs\":[\"http:\/\/www.halkynconsulting.co.uk\/\"],\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/author\/halkyn-consulting\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Threat Hunting - essential for every business - Halkyn Security Blog","description":"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/","og_locale":"en_GB","og_type":"article","og_title":"Threat Hunting - essential for every business - Halkyn Security Blog","og_description":"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.","og_url":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/","og_site_name":"Halkyn Security Blog","article_published_time":"2017-09-12T19:17:32+00:00","og_image":[{"width":1996,"height":1261,"url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/ThreatHunting_PewPew.png?fit=1996%2C1261&ssl=1","type":"image\/png"}],"author":"Halkyn Security","twitter_card":"summary_large_image","twitter_creator":"@HalkynSecurity","twitter_site":"@HalkynSecurity","twitter_misc":{"Written by":"Halkyn Security","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#article","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/"},"author":{"name":"Halkyn Security","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/3cfcd2267f12bbcce6a10159022c3df2"},"headline":"Threat Hunting &#8211; essential for every business","datePublished":"2017-09-12T19:17:32+00:00","dateModified":"2017-09-12T19:17:32+00:00","mainEntityOfPage":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/"},"wordCount":1041,"commentCount":0,"publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"keywords":["Cyber Security","Information Security","Security","Threat Hunting"],"articleSection":["Security"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#respond"]}]},{"@type":"WebPage","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/","url":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/","name":"Threat Hunting - essential for every business - Halkyn Security Blog","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website"},"datePublished":"2017-09-12T19:17:32+00:00","dateModified":"2017-09-12T19:17:32+00:00","description":"Threat hunting is essential. Every business needs a strategy and process to hunt for attackers. Here are some simple steps to get started.","breadcrumb":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2017\/09\/threat-hunting-essential-every-business\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Halkyn Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/"},{"@type":"ListItem","position":2,"name":"Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Threat Hunting &#8211; essential for every business"}]},{"@type":"WebSite","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","name":"Halkyn Security Blog","description":"Specialist Security &amp; Risk Management Consultants","publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization","name":"Halkyn Consulting","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","width":"990","height":"170","caption":"Halkyn Consulting"},"image":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/2329571","https:\/\/twitter.com\/HalkynSecurity"]},{"@type":"Person","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/3cfcd2267f12bbcce6a10159022c3df2","name":"Halkyn Security","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4126abc936773e5e8bd38e030d54306e161190a7d6166dba7edadb6caf13b504?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4126abc936773e5e8bd38e030d54306e161190a7d6166dba7edadb6caf13b504?s=96&d=retro&r=g","caption":"Halkyn Security"},"description":"Halkyn Security Consultants.","sameAs":["http:\/\/www.halkynconsulting.co.uk\/"],"url":"http:\/\/www.halkynconsulting.co.uk\/a\/author\/halkyn-consulting\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2017\/09\/ThreatHunting_PewPew.png?fit=1996%2C1261&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9yHvD-pk","jetpack_likes_enabled":true,"_links":{"self":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/comments?post=1570"}],"version-history":[{"count":21,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1570\/revisions"}],"predecessor-version":[{"id":1595,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/1570\/revisions\/1595"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media\/1572"}],"wp:attachment":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media?parent=1570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/categories?post=1570"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/tags?post=1570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}