Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on telemetry data and actively search for these patterns using AI and human expertise. A recent example highlighted the discovery of KongTuke C2 activity through correlating firewall and endpoint data, demonstrating the value of this proactive approach.
Cisco Talos employs a hypothesis-driven threat hunting methodology, moving beyond reactive alert systems. Their approach focuses on proactively identifying emerging threats by formulating specific hypotheses about adversary behavior based on telemetry data. This involves analyzing network traffic, endpoint activity, and other security signals to uncover patterns that traditional detection rules might miss. The use of AI and human analysts working together allows for a more nuanced understanding of the threat landscape.
The article illustrates this with several examples, including the identification of Python User-Agent connections, MSIEXEC activity, and DGA detection. A key case study showcases the discovery of KongTuke C2 activity through the correlation of firewall and endpoint data. The firewall initially identified outbound connections to a known malicious IP address, while endpoint telemetry revealed the execution of PowerShell and a Base64-encoded payload. This combined analysis, which neither source could have achieved alone, demonstrates the power of a holistic threat hunting approach.
Talos’ threat hunting operates continuously, leveraging data from nearly 50 million sensors. The AI engine executes hunts at scale, surfacing potential threats for human analysts to investigate. This proactive approach allows Talos to identify and respond to threats before they cause significant damage, providing customers with enhanced visibility and protection.
