Organizations Are Finding Threats More Effectively: Results of a SANS Survey

Bethesda, MD, September 4, 2018 – A new SANS survey finds that organizations are broadening the scope of their threat hunting efforts and that dwell times are decreasing. The survey, to be released in a two-part webcast on September 19 and September 20, also indicates that threat hunting is not so much “about rebranding what many defenders have endeavored to do over the years,” according to SANS authors Robert M. Lee and Rob T. Lee. Instead, they say, threat hunting is now “about placing an appropriate, dedicated focus on the effort by analysts who purposely set out to identify and counteract adversaries who may already be in the environment.”

The survey found 43% of respondents’ organizations are now performing continuous threat hunting operations, which the authors consider a strong indicator that threat hunting is growing in scope and need. As they point out, “In 2017, the number was only 35%, which shows that many organizations are now adopting methodologies that are key to reducing adversaries’ overall dwell time.”

The authors are hopeful that, as more organizations perform threat hunting, dwell time will shorten even more in the coming years. They indicate that dwell time currently averages above 90 days, but “as recently as 2013, the average dwell time was over six months. The decline since then shows that the adoption of threat hunting and stronger analytical techniques have had a significant impact on reducing the overall dwell time of adversaries across most networks.”

Full results will be shared during a two-part webcast. Part 1, covering prerequisites organizations should consider when preparing for a hunt, will be held on September 19 at 1 PM EDT. The Part 2 webcast, airing on September 20 at 1 PM EDT, will cover benefits and drawbacks of integrating with cyber threat intelligence (CTI). Both webcasts are sponsored by AnomaliDomainToolsIBMMalwarebytesQualysRiskIQ and hosted by SANS.

Register to attend the September 19 webcast at www.sans.org/webcasts/107450 and the September 20 webcast at www.sans.org/webcasts/107455.

Those who register for the webcast will also receive access to the published results paper developed by Robert M. Lee and Rob T. Lee.

Tweet This:

SANS Threat Hunting Survey | Scope of threat hunting is growing | Sept. 19 | www.sans.org/webcasts/107450

SANS Threat Hunting Survey | Threat hunting decreases dwell time | Sept. 20 | www.sans.org/webcasts/107455

Learn how the scope of threat hunting is growing, and why dwell time is shrinking | Part 1, www.sans.org/webcasts/107450 | Part 2, www.sans.org/webcasts/107455