Awesome
<p align='center'> <a href="https://twitter.com/Ch33r10"><img height="30" src="https://github.com/ch33r10/BlackHatAsia2020/blob/master/img/twitter%20blue%20logo.png"></a> <a href="https://www.linkedin.com/in/xena-olsen/"><img height="30" src="https://github.com/ch33r10/BlackHatAsia2020/blob/master/img/linkedin%20logo.png"></a> </p> <h3 align="center">PAINT IT, BLUE Slides - <a href="https://github.com/ch33r10/BlueSpace2021/blob/main/rock/Talk_2021_Paint_it_Blue.pdf">Link</a></h3> <p align="center">Pro Tips on transitioning from CTI to Hunt</p> <hr></hr> <p><h1 align="center">πΈ<b>RESEARCH</b></h1></p> <p></p> <h3 align="left">π₯<b>GOAL = ASK BETTER QUESTIONS</b></h3>
SOCIAL MEDIA & MORE | SANS | WORKSHOPS / TALKS | DISCORDS / SLACKS |
---|---|---|---|
#HuntingTipOfTheDay, Follow Threat Hunting Accounts EVERYWHERE - <a href="https://twitter.com/i/lists/1445402146434867206">Link</a> | Reading Room - <a href="https://www.sans.org/white-papers/">Link</a>, Webcasts - <a href="https://www.sans.org/webcasts/">Link</a> & Threat Hunting Summit | Prioritize Threat Hunting Talks/Workshops & take a look at YouTube | Join Slack/Discord related to infosec (BlueSpace has a Discord Channel - <a href="invite.gg/bluespace">Link</a>) |
TRAININGS / HANDS-ON | GIVE A TALK | HUNT HYPOTHESIS DEV | WORK PROJECTS |
---|---|---|---|
Boss of the SOC (BOTS) - <a href="https://live.splunk.com/splunk-security-dataset-project">BOTS v1</a>, <a href="https://events.splunk.com/BOTS_2_0_datasets">BOTS v2</a>, <a href="https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.html">BOTS v3</a>, ATTACK Range - <a href="https://github.com/splunk/attack_range">Link</a>, SPLUNK, <a href="https://conf.splunk.com/">.conf</a> Talks, SPLUNK <a href="https://www.splunk.com/en_us/about-us/events.html">Workshops</a> | Talk about something HUNT adjacent | Read Threat Reports & Think about how YOU would HUNT it, Understand the Technical Attack Chain | Volunteer to work SOC tickets, Volunteer to prep CTI reports for HUNT/PURPLE |
MITRE ATT&CK TECHNIQUES | CISA / PUBLIC THREAT REPORTS | INFOSEC CURRENT EVENTS |
---|---|---|
Pick a few and be able to explain them in DETAIL - <a href="https://attack.mitre.org/">MITRE ATT&CK</a> | Develop Hunt Hypotheses with a minimum of 1 hour of content to discuss | Develop hunt scenarios & understand the technical attack chain |