Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 18 of 25
Principle C2 Threat Hunting
Capabilities exist to ensure security defences remain effective and to detect cyber security events and incidents adversely affecting, or with the potential to adversely affect, essential function(s).
Principle
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description of principle
Some cyber-attacks may evade your automated detections and alerting, particularly more sophisticated threats where their ability to evade detection is likely higher. Where this is the case, threat hunting should be leveraged to detect these threats. Threat hunting is the proactive, iterative and human-centric identification of Cyber threats that have evaded existing security controls
Your monitoring and detection teams should be able to proactively hunt for and detect the signs of adverse activity that may have evaded the detection of existing security controls. An organisation performing this at a cadence that matches the risks posed to them is best practice. However, if an organisation is unable to do this but can perform threat hunting on an ad hoc basis, for example in response to a tip off from a government organisation, risk will likely be reduced to some degree.
The exact steps an organisation should follow when performing threat hunting will likely vary between organisations. Threat hunts may also enable your organisation to create automated detections based on the procedure followed during the threat hunt.
Examples of approaches you may decide to follow when performing threat hunts are:
-
Hypothesis Driven – This is the most classically known approach where threat hunters form a supposition about a threat or the activities of a threat and use threat hunts to prove or disprove their hypothesis.
-
Baseline or Anomaly Based Hunts – In this approach threat hunters manually (can be assisted automation) identify what is ‘normal’ and then identify deviations from this baseline for further analysis and investigation.
-
Advanced Analytics and Machine Learning – This approach leverages data analytics and machine learning alongside big data to detect irregularities. These irregularities are then investigated to determine what action should be taken.
Threat hunting relies on having appropriately skilled and experienced personnel, the necessary tools and data, an understanding of systems and user behaviour as well as threat intelligence. In other words, threat hunting relies heavily on elements of Principle C1 being in place and effective.
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
- 1
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
- 2
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
The science of anomaly detection, which goes beyond using pre-defined or prescriptive pattern matching, is a challenging area. Capabilities like machine learning are increasingly being shown to have applicability and potential in the field of intrusion detection. However, if they are not well designed and executed, these technologies can be expensive, difficult to implement and can produce high false-alarm rates. Organisations that want to use such tools should consult the NCSC's guidance on Intelligent Security Tools.
C2.a Threat Hunting
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
You do not know the resources required for threat hunting. You do not have access to an effective threat hunting capability. Your threat hunts do not follow any structure and few if any records are created. | You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis. You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source). Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections. You document details of threat hunts and post hunt analysis. | You understand the resources required to perform threat hunting and these are deployed as part of business as usual. You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s). Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections. You turn threat hunts into automated detections and alerting where appropriate. You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture. You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s). You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated). Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc). |


