Threat hunting is still new and poorly defined from a process and organizational standpoint. Most organizations are still reacting to alerts and incidents instead of proactively seeking out the threats. Many organizations are finding success by focusing on core continuous monitoring technologies and relying on more security automation in their environments to make hunting more effective.Download this survey report which also includes information surrounding:Critical DFIR skills for threat hunting and the hunting armory (effective tools and resources) How to measure hunt team success is also included in the report.”]
Source: https://www.bankinfosecurity.com/whitepapers/sans-2018-threat-hunting-survey-w-4722

