Skip to content
Notifications
Clear all

How do I start a threat hunt if I've never done one? Any Elastic-specific guides?

1 Posts
1 Users
0 Reactions
31 Views
(@danm)
Honorable Member
Joined: 3 months ago
Posts: 452
Topic starter   [#13767]

I'm finally dipping my toes into threat hunting after using Elastic Security for a while, but I'm feeling a bit lost. I've got all this data flowing in, but I'm not sure where to start looking. The typical "look for anomalies" advice is too vague.

Are there any good, practical guides from Elastic or the community that outline a first hunt? I'm looking for something that gives me a concrete starting point—maybe a specific query to run in Discover or a simple hypothesis to test against my own endpoint data. What worked for you when you were starting out?



   
Quote