CySA+ v4 · Objective 1.4
Threat intelligence and hunting
Turn external threat information into locally relevant hypotheses. Evaluate confidence, map behaviour, and design hunts whose results can improve detection.
What you will be able to do
- Assess intelligence for timeliness, relevance, and accuracy.
- Distinguish atomic indicators from behavioural evidence.
- Map a threat hypothesis to ATT&CK and observable data.
- Design a scoped hunt or deception control with explicit limitations.
Learn the concepts
- Lesson 1
Turn intelligence into a local decision
Threat information becomes intelligence when it helps somebody make a decision. A long indicator feed is less useful than a well-supported answer to a specific local question.
Open lesson → - Lesson 2
Design a hunt you can learn from
A hunt deliberately searches for activity that routine detection may have missed. Its value comes from a testable hypothesis and a clear account of what the available evidence can establish.
Open lesson →
Apply your judgement · Synthetic scenario
The untested green heat map
A team reports strong credential-abuse coverage because its ATT&CK dashboard is mostly green. A new intelligence report describes misuse of dormant service identities.
- Dashboard legend
- Green means a rule has been created, not tested
- Identity inventory
- 27 dormant service accounts; 8 permitted interactive access
- Telemetry
- Authentication logs retained for 14 days; process records absent on 3 legacy hosts
- Intelligence
- Recent report describes interactive use followed by sensitive file access; no matching local IoC yet
Your task
- Define a scoped behavioural hunt and an expected benign explanation.
- Explain why the dashboard cannot establish detection effectiveness.
- Specify how positive and negative results should change operations.
Compare your response
Search retained authentication records for interactive use of the eight eligible dormant accounts, then correlate available host and file-access evidence. Check scheduled maintenance and reactivated applications as alternatives.
The map records rule existence, not validated detection. Missing process telemetry limits conclusions on the legacy hosts, and absence of a supplied IoC does not negate a behavioural hypothesis.
Escalate unexplained corroborated use through response procedures. For a negative result, document scope and blind spots, test representative detections, and review unnecessary interactive access with account owners.
Put it into practice
Use these labs alongside this module.
Check your understanding
Source reading: supplied book, chapters 4, 5. Lessons, scenarios, and questions are original CyberCorps course material.