It may be an old Dutch saying, but some IT administrators manage their IT environments from ivory towers and behave accordingly. Would you dare admit out loud that 'your network' might not be quite as fully protected from the hostile outside world as you thought? Just as people are often the weak link in protecting IT systems and data, the system administrator's vulnerability is a sensitive issue for the new IT security strategy: cyber threat hunting.
Why is threat hunting so important, and why do we devote so much time and attention to it? First, because of the constant stream of malware and threats that organisations and individuals face online. We all know the familiar, age-old computer viruses, the often childish (but still dangerous) spam and phishing messages, and the adware trying to infect us with malware through advertisements. But hackers are clever and becoming cleverer: in an endless 'rat race', they constantly develop themselves and their tools to ever higher levels. Not only to stay ahead of security solutions, but above all because the stakes keep rising.
More than ever, IT systems contain valuable, irreplaceable data and have become essential to businesses, governments and individuals alike. In healthcare institutions, sometimes literally vital. Ransomware attacks are now notorious and commonplace. Businesses large and small have repeatedly fallen victim to systems and data being held hostage, leaving them to pay often substantial sums or restore backups that are frequently too old.
Modern next-generation unified threat management firewalls, machine learning antimalware with artificial intelligence, deep learning cloud applications and neural networks</em>; everything is deployed to keep the malicious internet out, often with reasonable success. The average system administrator feels reassured and assumes their 'state-of-the-art' security has closed every door and will keep it that way. But is that true? Only a few security solutions can genuinely detect in time how and when malware and ransomware settle into system memory: almost invisible, encrypted in an unusual way, and disguised as system components.
Organisations with an existing EDR (Endpoint Detection and Response) solution assume they have everything in order. They are nevertheless often approached to have their IT environment checked for malware. If that extra check works in the same way as the security solution already in place, the assessment serves no real purpose and yields little or no new information. Such a wasted investment can only be avoided by using different methods and new, alternative and better approaches.
Cyber threat hunting is therefore every IT administrator's best friend, starting from the assumption that systems may already be infected. Cyber threat hunting supports the IT administrator in their fight, directly and indirectly. The most advanced hacker does not immediately reveal themselves after successfully getting in. Instead, they settle down for a while, let their malware look around, listen in on the neighbours and map the environment. When the moment comes, the malware can act decisively: system passwords are already known, the environment's IP addresses have been mapped, and security processes hold no secrets. Everything is ready for a highly effective attack. Why did nobody see it coming?
With our cyber threat hunting service, we search your network for those hiding places, those sleeper cells waiting for their moment: the nightmare of your IT administrator and everyone responsible for data integrity. These threats can hide and embed themselves in many different ways across systems and data. That is why we use an extensive toolkit containing the world's best forensic investigation tools, complemented by the expertise and manual interpretation of our own highly experienced, practical security analysts. Just as importantly, we do not search aimlessly; we work only with accepted, widely recommended methodologies. This allows the outputs of all those tools to fit together and form a sound report. We follow widely accepted frameworks, including Sqrrl and TaHiTi for financial institutions, with specific adaptations for, among others, SMEs in manufacturing. Searching and finding is useful, but explaining the dangers and risks and advising on the best solution is the real purpose of our threat hunting services.
Cyber Threat Hunting is not a threat to an IT administrator, but an additional tool to protect their network against direct and indirect threats, data loss, system outages and GDPR compliance problems.
