Files
Anthropic-Cybersecurity-Skills/skills/detecting-evasion-techniques-in-endpoint-logs/assets/template.md
T

40 lines
833 B
Markdown

# Evasion Detection Hunt Template
## Hunt Information
| Field | Value |
|-------|-------|
| Hunt Name | |
| Target Technique | MITRE ATT&CK ID |
| Hypothesis | |
| Data Sources | Sysmon / Windows Security / EDR |
| Time Range | |
| Analyst | |
## Detection Queries
| SIEM | Query | Expected Results |
|------|-------|-----------------|
| Splunk | | |
| Elastic KQL | | |
| MDE Advanced Hunting | | |
## Findings
| Timestamp | Host | Technique | Severity | Evidence | True/False Positive |
|-----------|------|-----------|----------|----------|-------------------|
| | | | | | |
## Tuning Actions
| Finding | Action | New Exclusion | Status |
|---------|--------|---------------|--------|
| | Allow / Investigate / Block | | |
## Sign-Off
| Role | Name | Date |
|------|------|------|
| Threat Hunter | | |
| SOC Lead | | |