Cyber investigations, threat hunting and research: More art than science

Source
Advertisement


While it’s true that threat hunting, incident response, and threat research all have their foundations in science (operating system theory and architecture, computer language and compilation, protocols, hardware and memory architecture, logic, etc.), throughout my entire career I have found it is also fundamentally true that the most successful threat hunters, incident responders, and threat researchers are far more artist than scientist.

In fact, this is the very summary of all the advice I’ve offered in my last three Help Net Security articles: if you want to land a job and have a successful career as a researcher, threat hunter or investigator, approach the work creatively, as play, and with a beginner’s mind.

Advertisement