All Mars guides in the Threat Hunting category.
Showing 8 guides in Threat Hunting
Learn what a threat intelligence platform ingests, scores, and exports, which seven functions are worth paying for, and where its output stops short of defense.
Threat hunting is the search for attacker activity no alert has flagged. Learn how a hunt runs from hypothesis to deployed detection, and how to measure it.
Proactive threat hunting covers the twelve days between a public CVE advisory and the first published detection rule, with a method for measuring your own gap.
Score threat intelligence against your own assets, identities, and telemetry to decide which reports earn a hunt, which need coverage work, and which get archived.
Compare threat hunting vs threat intelligence by what each answers, how each fails, and the hypothesis that turns an outside report into a query on your data.
Learn what AI threat hunting contributes to a hunt, where human analysts still outperform a model, and how to judge any vendor's detection accuracy claim.
Cloud threat hunting starts after the host is gone. Compare log sources and retention defaults across AWS, Azure, and Google Cloud, then scope your hunt.
EDR threat hunting means querying endpoint telemetry beyond what existing alerts cover. Get five hunts to run this week, the benign look-alikes, and five mistakes to avoid.