Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 18 of 25

Principle C2 Threat Hunting

iStock.com/Think Neo

Capabilities exist to ensure security defences remain effective and to detect cyber security events and incidents adversely affecting, or with the potential to adversely affect, essential function(s).



Threat hunting relies on having appropriately skilled and experienced personnel, the necessary tools and data, an understanding of systems and user behaviour as well as threat intelligence. In other words, threat hunting relies heavily on elements of Principle C1 being in place and effective.


The science of anomaly detection, which goes beyond using pre-defined or prescriptive pattern matching, is a challenging area. Capabilities like machine learning are increasingly being shown to have applicability and potential in the field of intrusion detection. However, if they are not well designed and executed, these technologies can be expensive, difficult to implement and can produce high false-alarm rates. Organisations that want to use such tools should consult the NCSC's guidance on Intelligent Security Tools.

C2.a Threat Hunting

 

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

You do not know the resources required for threat hunting.

You do not have access to an effective threat hunting capability.

Your threat hunts do not follow any structure and few if any records are created.

You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.

You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).

Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.

You document details of threat hunts and post hunt analysis.

You understand the resources required to perform threat hunting and these are deployed as part of business as usual.

You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).

Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.

You turn threat hunts into automated detections and alerting where appropriate.

You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.

You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).

You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).

Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).


Published

Reviewed

Version

4.0