Opens in a new tab
vmblog logo 2024 wht (updated)

Working as a threat hunter means expecting the unexpected

Share: 

David Marshall | Published: October 4, 2022

By Connor Morley, senior threat hunter, WithSecureTM

Being a threat hunter is a demanding, challenging and yet rewarding job as no two days play out the same and every incident creates new obstacles to overcome. Our skills are in high demand due to the threat landscape becoming ever more complex and daunting as time goes on. The unfortunate truth is that attackers are never going away. Hence there is a huge demand for threat hunters globally.

Defeating cyber-criminals means you have to think like them

Attackers often have an advantage over defenders because they only need to find that one vulnerability in an organization’s network to get in and start wreaking havoc. A big part of a threat hunter’s job is to identify any weak entry points before threat actors can discover them and proceed to exploit them.

This requires a threat hunter to put themselves in the mind of an attacker, to think like a malicious attacker in order to identify the most likely routes of ingress and exploitation. By thinking and training, like an offensive actor, threat hunters can anticipate how an estate may be attacked and, if breached, how an attacker may proceed through a network. This provides the means by which defenders can find, identify, and neuter threats.

Becoming a threat hunter

Before joining the industry, I studied Computer Security and Forensics at university, focusing on such things as offensive techniques, forensics analysis, and penetration testing. I was offered the opportunity to complete a doctorate at the university after having graduated with a First-Class Honours degree. However, after finding out about a job in F-Secure’s Countercept team (now part of WithSecureTM) working on research-based active defense, I decided to take the plunge, subsequently going into my current role as a senior threat hunter.

The title of “threat hunter” has been around for several years and can conjure up images of noble heroes going into battle with supervillains in the digital realm or the more reality-based impression that we spend our time expelling bad-intentioned intruders out of a network. These perceptions, while certainly media-sexy, aren’t quite the case. Instead, we focus on working to find potential attack paths that threat actors might seek to exploit, and we do this by creating standard rules and toolsets that detect malicious behavior.

Threat hunters also often conduct hunt sprints, long sessions designed to expose vulnerabilities based on new and emerging exploits and techniques and collected incident data. These sprints are effective for building short-term and future protection for clients. The intel gathered in hunt sprints is also used to build obstacles, such as network speed bottlenecks that hinder an attackers’ progress and gives defenders vital time to expel them from the system, lock them out and ensure they are never able to get back in again. During a sprint, hunters sweep across their clients’ estates to discover compromises based on the pre-conditions set out in the hunt’s rules. Findings are then collated and analyzed to create bespoke detection capabilities that alert organizations when attackers use certain techniques.

There are occasions when we come across a threat actor poking around in the network, and this can be a rather intense moment when they know that you are aware of their presence, especially as they might change their tactics to try and shake us off. Moreover, they might even decide to engage in the nuclear option and do as much damage as possible before being kicked out of the network. For this reason, threat hunters need to tread very carefully when on the hunt.

Staying on top of rapid industry developments

In order to keep up with threat actors, threat hunters have to keep their ears to the ground in both their daily operations and the wider industry. This means careful analysis and logging of any encountered techniques or tools as well as tapping into the rich cybersecurity industry and culture, which continuously pushes what is deemed possible or safe on modern systems.

How this information is accumulated varies, but through certain social media platforms, conventions, or even simple word of mouth valuable information is passed across the industry fairly quickly. The issue is determining which areas or subjects are of the most value and how much studying and planning time is required. As computers and their users are becoming ever more advanced, it is impossible to keep abreast of everything; as such, it is a judgment call based on risk, which determines the areas we focus on.

For example, one such area is insider threats which is an ever-growing concern in technological industries, and which are often difficult for hunters to predict and combat. In response to this, we’re seeing the rise of models like zero trust, which is a tight security framework based on the concept of verifying but never trusting. One of the primary reasons for the roll-out of zero trust is the growth of insider threats, which are often difficult for hunters to predict and combat. After all, no amount of analysis and careful penetration testing can stop a disgruntled employee who one day logs on using their privileged account and steals millions of pounds worth of sensitive information.

We threat hunters never sit idle but unfortunately, neither do attackers. This is why the job of a threat hunter is so interesting and challenging. Every attack and vulnerability is a new puzzle to solve.

##

ABOUT THE AUTHOR

Connor-Morley 

Connor Morley is a senior security researcher at WithSecure. A keen investigator of malicious TTPs, he enjoys experimenting and dissecting malicious tools to determine functionality and developing detection methodology. As a researcher and part time threat hunter, he is experienced with traditional and ‘in the wild’ malicious actors’ behaviour.