CySA+ v4 · Objective 1.4

Threat intelligence and hunting

Turn external threat information into locally relevant hypotheses. Evaluate confidence, map behaviour, and design hunts whose results can improve detection.

What you will be able to do

  • Assess intelligence for timeliness, relevance, and accuracy.
  • Distinguish atomic indicators from behavioural evidence.
  • Map a threat hypothesis to ATT&CK and observable data.
  • Design a scoped hunt or deception control with explicit limitations.

Learn the concepts

  1. Lesson 1

    Turn intelligence into a local decision

    Threat information becomes intelligence when it helps somebody make a decision. A long indicator feed is less useful than a well-supported answer to a specific local question.

    Open lesson →
  2. Lesson 2

    Design a hunt you can learn from

    A hunt deliberately searches for activity that routine detection may have missed. Its value comes from a testable hypothesis and a clear account of what the available evidence can establish.

    Open lesson →

Apply your judgement · Synthetic scenario

The untested green heat map

A team reports strong credential-abuse coverage because its ATT&CK dashboard is mostly green. A new intelligence report describes misuse of dormant service identities.

Dashboard legend
Green means a rule has been created, not tested
Identity inventory
27 dormant service accounts; 8 permitted interactive access
Telemetry
Authentication logs retained for 14 days; process records absent on 3 legacy hosts
Intelligence
Recent report describes interactive use followed by sensitive file access; no matching local IoC yet

Your task

  1. Define a scoped behavioural hunt and an expected benign explanation.
  2. Explain why the dashboard cannot establish detection effectiveness.
  3. Specify how positive and negative results should change operations.
Compare your response

Search retained authentication records for interactive use of the eight eligible dormant accounts, then correlate available host and file-access evidence. Check scheduled maintenance and reactivated applications as alternatives.

The map records rule existence, not validated detection. Missing process telemetry limits conclusions on the legacy hosts, and absence of a supplied IoC does not negate a behavioural hypothesis.

Escalate unexplained corroborated use through response procedures. For a negative result, document scope and blind spots, test representative detections, and review unnecessary interactive access with account owners.

Put it into practice

Use these labs alongside this module.

Check your understanding

Choose the best response to each scenario, then check your reasoning. These are course practice questions.

1. Three intelligence feeds repeat a single unverified report. Which assessment is strongest?
2. A hunt returns no results from a source missing half its expected hosts. What should be concluded?
3. An organisation wants a decoy credential to detect unauthorised access attempts. Which design is most appropriate?

0 of 3 answered

Source reading: supplied book, chapters 4, 5. Lessons, scenarios, and questions are original CyberCorps course material.