David J. Bianco Profile picture
Threat Hunting, CTI, incident detection & response. SANS instructor. Special interest in helping newbies get started. He/Him. https://t.co/XcrBqQLUrP
Feb 17, 2021 9 tweets 3 min read
I've had something in my mind now for a few years, but I never published it. So today, you're getting a short thread on "How to Prepare for #ThreatHunting Using the ABLE Framework".

1/9
Good threat hunting starts with a hypothesis. This is, loosely, an educated guess at a type of malicious activity which may be happening. @RobertMLee and I wrote a whitepaper on this, called "Generating Hypotheses for Successful Threat Hunting": sans.org/reading-room/w…

2/9