Threat Hunting and Threat Intelligence Questions

Proactively pursuing adversaries and operationalizing knowledge of them. Covers threat hunting and hypothesis-driven investigation, threat intelligence collection and integration, indicators of compromise, the MITRE ATT&CK framework, advanced persistent threats, and situating activity within the current threat landscape. The 'go find what the alerts missed, informed by adversary knowledge' discipline.

HardTechnical
25 practiced

During a complex, protracted incident you observe overlapping activity sets possibly from multiple adversary groups. Describe a method to separate activity streams, attribute actions to likely actors, prioritize containment and remediation when indicators overlap, and how to present attribution confidence and remediation prioritization to leadership without compromising ongoing evidence collection.

HardTechnical
23 practiced

A sophisticated attacker uses living-off-the-land binaries (LOLBAS) and scheduled tasks to persist on endpoints and exfiltrate slowly via small periodic uploads. Draft a comprehensive threat-hunting plan: hypotheses, required telemetry, analytic detections (including anomaly baselines), containment procedures, and how you'd measure hunt success.

HardTechnical
26 practiced

Design a two-week threat-hunting engagement aimed at detecting stealthy command-and-control (C2) communication that uses domain fronting and intermittent beaconing. Define hypotheses to test, telemetry sources to collect (DNS, TLS SNI, netflow, proxy logs), hunting queries or analytics to apply, and validation steps for suspected findings.

EasyTechnical
25 practiced

Given limited engineering resources, describe a pragmatic approach an Information Security Analyst would use to prioritize ATT&CK techniques for new detection development across the enterprise. Include at least three factors you would weigh and a simple scoring or ranking method.

MediumTechnical
20 practiced

Write a Sigma rule (YAML) that detects processes launching PowerShell with base64-encoded commands (i.e., contains '-EncodedCommand' or '-enc'). Include fields for title, description, detection selection, false-positive notes, and a mapping to an ATT&CK technique.

Unlock Full Question Bank

Get access to all Threat Hunting and Threat Intelligence interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.