Section 3: Working with a Research Environment
This third part of this book is going to be the most technical one, since we are going to cover how to set up a Windows research environment and prepare it so that we can start hunting using various open source tools, like those created by José and Roberto Rodriguez: OSSEM, Mordor, and The Threat Hunter Playbook among others. We are also going to use Atomic Red Team to carry out atomic hunts and MITRE CALDERA to emulate the adversary. Finally, we are going to close this section by discussing two crucial parts of the process: documentation and automation.
This section comprises the following chapters:
- Chapter 7, Creating a Research Environment
- Chapter 8, How to Query the Data
- Chapter 9, Hunting for the Adversary
- Chapter 10, Importance of Documenting and Automating the Process