This paper, authored by Robert M. Lee and Rob Lee from the SANS Institute, provides an overview of threat hunting.

The paper explains:

  • What threat hunting is (and what it is not)
  • Why it is needed
  • When threat hunting is appropriate
  • Where it fits into maturity efforts
  • How to get started and who should do the hunting

Sqrrl + SANS Threat Hunting White Paper