Threat Hunting Techniques & Indicators Flashcards
CompTIA CySA+ CS0-004 (V4) Flashcards

| Front | Back |
| Best practice for managing false positives | Iteratively tune detections and document legitimate baselines to reduce noise |
| Common host data sources | Process logs file system events autoruns EDR telemetry and system audit logs |
| Common network data sources | Netflow packet captures proxy logs DNS logs and firewall logs |
| Define hypothesis driven hunting | An investigative approach that starts with a testable assumption about potential adversary activity to guide data collection and analysis |
| Describe enrichment | Adding context like asset owner geolocation or threat intel to raw telemetry to improve analysis |
| Explain query strategy broad to narrow | Start with wide data queries to identify anomalies then refine to isolate true positives |
| Explain query strategy hypothesis driven | Design queries specifically to test the hunting hypothesis using relevant telemetry |
| Give an example of a high value artifact for pivoting | Authentication logs that show unusual logon sequences or host access |
| How to handle high confidence IOC found in production | Isolate affected assets collect volatile evidence and escalate to containment and remediation |
| How to reduce detection gaps | Map telemetry to ATT&CK identify missing coverage and deploy sensors or rules to collect needed data |
| How to validate a suspected IOC | Correlate across multiple data sources and reconstruct activity timeline to confirm maliciousness |
| How use threat intel to prioritize hunts | Focus on intel linked to your environment like targeted industries or known exploited services |
| IOA definition | Indicator of Attack behavior pattern or sequence that suggests intent or ongoing malicious activity |
| IOC definition | Indicator of Compromise observable artifact like file hash IP or domain that signals past or current compromise |
| Key metrics for hunting success | Detections validated time to detect time to remediate and reduction in false positives |
| List the typical hunt phases | Preparation Detection Hypothesis Investigation Validation and Remediation |
| Primary difference between IOC and IOA | IOC is static evidence of compromise IOA reflects behavior or intent |
| Purpose of hunting exercises like purple teaming | Test and improve detection by collaborating between offensive and defensive teams |
| Role of EDR in hunting | Provides rich endpoint telemetry process and command line details for detection and containment |
| Role of PCAP and full packet capture | Enables deep protocol level analysis and reconstruction of network sessions for validation |
| Role of SIEM in hunting | Aggregates logs correlates events and enables searching across diverse telemetry at scale |
| What are TTPs in threat hunting | Tactics Techniques and Procedures used by adversaries to achieve objectives |
| What belongs in the Preparation phase | Define hypothesis identify data sources ensure telemetry and tools are available |
| What is a false positive in hunting | An alert or finding that appears malicious but is benign on investigation |
| What is a hunting playbook | A repeatable documented procedure for conducting a specific hunt including queries and evidence collection |
| What is a hypothesis in hunting | A falsifiable statement about malicious activity to be tested with data |
| What is a kill chain in hunting | Sequential stages of an intrusion used to map detections and identify gaps in coverage |
| What is an enriched IOC | An IOC combined with context such as first seen time asset owner and related alerts |
| What is baseline behavior | Normal activity patterns for users systems and applications used to detect anomalies |
| What is behavioral analytics | Detecting deviations from normal behavior patterns to identify suspicious activity |
| What is dwell time | The duration an adversary remains in an environment before detection |
| What is enrichment via external feeds | Augmenting telemetry with reputation tags vulnerability data or actor attribution from feeds |
| What is hypothesis prioritization | Prioritizing hunts based on impact likelihood and data availability |
| What is pivoting in an investigation | Using one artifact to find related artifacts or hosts to expand scope of activity |
| What is threat intelligence integration | Ingesting and applying external context like adversary TTPs indicators and reports to inform hunts |
| What is timeline analysis | Reconstructing sequence of events across data sources to understand attacker actions and scope |
| When to use anomaly detection | When you lack signatures for novel or evolving attacker behavior |
| When to use host logs vs network logs | Use host logs for process file and user activity and network logs for lateral movement and data exfiltration |
| Why document hunt results | Preserves lessons learned enables reuse of methods and supports remediation and reporting |
| Why retention matters | Longer telemetry retention enables detection of long dwell attackers and historical investigations |
| Why threat modeling matters for hunting | Helps prioritize likely attack paths assets and controls to focus hypotheses |
| Why use ATT&CK in hunting | Provides a common framework to map adversary behaviors to techniques and gaps |
About the Flashcards
Flashcards for the CompTIA CySA+ exam help students review threat hunting terminology, including hypotheses, adversary TTPs, indicators of compromise, indicators of attack, dwell time, and baseline behavior. The deck also explains typical hunt phases, prioritization methods, investigation strategies, and documentation practices.
Students can reinforce their understanding of host and network telemetry, EDR, SIEM, packet capture, ATT&CK mapping, and threat intelligence integration. Additional cards cover anomaly detection, query refinement, pivoting, enrichment, timeline analysis, false-positive reduction, detection validation, remediation, hunting metrics, playbooks, and purple team exercises.
Topics covered in this flashcard deck:
- Threat hunting fundamentals
- IOCs, IOAs, and TTPs
- Hunt phases and hypotheses
- Telemetry and security tools
- Investigation and validation
- ATT&CK and threat intelligence