How are you showing value from your #ThreatHunting programs? I think a lot of teams really struggle with this, so interested in hearing others’ thoughts. Putting my $0.02 in the thread. 1/3
I think a lot of hunt teams look at findings as the holy grail, but I would argue that there are better ways to show value. One of the best I’ve found is to compare those hunt findings against true positive findings from other tools (other investments). 2/3
For example, how many hunt findings did you produce compared to the total findings worked by the SOC? If you really want to stand out, give your leaders data they’ve never seen before. If your metrics are only relevant to you, you probably aren’t playing your best hand. 3/3
• • •
Missing some Tweet in this thread? You can try to
force a refresh