mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-21 09:11:21 +03:00
40 lines
833 B
Markdown
40 lines
833 B
Markdown
# Evasion Detection Hunt Template
|
|
|
|
## Hunt Information
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| Hunt Name | |
|
|
| Target Technique | MITRE ATT&CK ID |
|
|
| Hypothesis | |
|
|
| Data Sources | Sysmon / Windows Security / EDR |
|
|
| Time Range | |
|
|
| Analyst | |
|
|
|
|
## Detection Queries
|
|
|
|
| SIEM | Query | Expected Results |
|
|
|------|-------|-----------------|
|
|
| Splunk | | |
|
|
| Elastic KQL | | |
|
|
| MDE Advanced Hunting | | |
|
|
|
|
## Findings
|
|
|
|
| Timestamp | Host | Technique | Severity | Evidence | True/False Positive |
|
|
|-----------|------|-----------|----------|----------|-------------------|
|
|
| | | | | | |
|
|
|
|
## Tuning Actions
|
|
|
|
| Finding | Action | New Exclusion | Status |
|
|
|---------|--------|---------------|--------|
|
|
| | Allow / Investigate / Block | | |
|
|
|
|
## Sign-Off
|
|
|
|
| Role | Name | Date |
|
|
|------|------|------|
|
|
| Threat Hunter | | |
|
|
| SOC Lead | | |
|