Threat Hunting
Threat Hunting is the proactive, hypothesis-driven search for threats that have evaded automated detection. CBRCOR covers threat-hunting techniques as an advanced SOC skill.
Threat Hunting is the proactive, hypothesis-driven search for threats that have evaded automated detection. CBRCOR covers threat-hunting techniques as an advanced SOC skill.
A Security Operations Center (SOC) is the team and facility that monitors, detects, and responds to security incidents.
A Security Information and Event Management (SIEM) system aggregates and correlates logs and alerts to detect threats.
Security Orchestration, Automation, and Response (SOAR) automates incident-response playbooks to accelerate detection and containment.
A Playbook is a documented, often automated sequence of response actions for a specific incident type.
Incident Response is the structured process of detecting, analyzing, containing, eradicating, and recovering from security incidents.
Threat Hunting is the proactive, hypothesis-driven search for threats that have evaded automated detection.
Threat Intelligence is curated information about adversaries, their infrastructure, and indicators used to inform detection and response.
MITRE ATT&CK is a knowledge base of adversary tactics and techniques used to map, detect, and reason about attacks.
An Indicator of Compromise (IOC) is an artifact — such as a hash, IP, or domain — that signals a possible intrusion.
Digital Forensics is the disciplined collection and analysis of evidence from hosts, networks, and memory during an investigation.
Chain of Custody is the documented, unbroken record of who handled evidence and when, preserving its integrity.
Risk Scoring quantifies the severity and priority of vulnerabilities and incidents, often using CVSS and business context.
The Common Vulnerability Scoring System (CVSS) rates vulnerability severity using standardized metrics.
Vulnerability Management is the ongoing process of identifying, prioritizing, and remediating security weaknesses.
API Integration connects security tools so data and actions flow automatically across the SOC toolchain.