Resources · Glossary

Threat hunting glossary

34 terms you will meet in threat hunting, detection engineering and threat intelligence, defined in plain words. Where Huntbase does something with a term, we say so in one line.

Backtesting

Running a detection rule or hunt query over historical data to see what it would have found: how often it fires, on which hosts and users, and whether it catches known incidents.

CACAO

Collaborative Automated Course of Action Operations

An OASIS standard for describing security playbooks in a machine-readable, vendor-neutral JSON format, so a course of action can be shared between organisations and run by different tools. Version 2.0 is current.

Where Huntbase fits: Huntbase can export hunt playbooks as CACAO v2. Threat Intelligence

Canary rollout

Staged rollout

Releasing a change to a small subset first, watching for problems, then widening it in stages. In security it applies to detection rules, agent updates and response scripts alike.

CVSS

Common Vulnerability Scoring System

An open standard, maintained by FIRST, for rating the severity of software vulnerabilities on a 0 to 10 scale based on how they can be exploited and what they affect. Version 4.0 was published in 2023.

Where Huntbase fits: Huntbase enriches findings with CVSS, EPSS and KEV in alert triage. AI Alert Triage

Detection engineering

The practice of designing, testing, deploying and maintaining detection rules as an engineering discipline: rules live in version control, are tested against real data, are tuned on evidence, and are measured once live.

Where Huntbase fits: Huntbase gives Sigma rules backtests, shadow mode and version history. Detection Engineering

EDR

Endpoint detection and response

Software on laptops, servers and workloads that records activity, detects threats and lets responders investigate and contain them, for example by isolating a host or killing a process.

Endpoint isolation

Host containment

Cutting a host off from the network, except for the connection to the security tool managing it, so an attacker cannot use it while responders investigate.

EPSS

Exploit Prediction Scoring System

A model, maintained by FIRST, that estimates the probability that a published vulnerability will be exploited in the wild in the next 30 days. It complements severity scores by describing likelihood rather than impact.

Hunt hypothesis

A testable statement that frames a hunt, such as "an attacker is using stolen credentials to sign in from proxy infrastructure". A good hypothesis can be proven wrong, names the data that would confirm or refute it, and is usually drawn from threat intelligence, ATT&CK techniques or something odd an analyst noticed.

Hunt playbook

A reusable, documented hunt: the hypothesis, the data it needs, the steps and queries, what a positive or negative result means, and its known blind spots.

hunt.md

An open, MIT-licensed format for threat hunt playbooks, published by Huntbase: Markdown with YAML frontmatter, one heading per step and fenced blocks for queries. It reads without tooling and diffs cleanly in version control.

Where Huntbase fits: The spec, examples and tooling are on GitHub. hunt.md spec

IOC

Indicator of compromise

An observable artefact that suggests a system has been compromised: a file hash, IP address, domain, URL, registry key or similar. IOCs are easy to share and match, but attackers can change them cheaply, so they age quickly.

KEV

CISA Known Exploited Vulnerabilities catalog

A list, maintained by the US Cybersecurity and Infrastructure Security Agency, of vulnerabilities with reliable evidence of exploitation in the wild. US federal agencies must remediate listed vulnerabilities by set deadlines, and many other organisations use it to prioritise patching.

KQL

Kusto Query Language

A read-only query language from Microsoft, written as a pipeline of operators. It is used in Azure Data Explorer, Microsoft Sentinel, Microsoft Defender advanced hunting and Azure Monitor.

Where Huntbase fits: Huntbase uses KQL as one query language across every connected store. Federated SIEM

Live response

Investigating a running host directly, rather than from logs: listing processes and connections, collecting files and memory, or running scripts. It answers questions the logs never recorded.

Where Huntbase fits: Huntbase Endpoint Control asks hosts live questions mid-hunt. Endpoint Control

MISP

An open-source threat intelligence platform for storing, correlating and sharing indicators and events, widely used by CERTs, ISACs and security teams. It began as the Malware Information Sharing Platform.

MITRE ATT&CK

A public knowledge base, maintained by MITRE, of adversary tactics and techniques observed in real intrusions. It covers enterprise, mobile and industrial control systems, and gives defenders a shared vocabulary for mapping detections, hunts and coverage gaps.

OCSF

Open Cybersecurity Schema Framework

An open schema for security event data, launched in 2022 by a group of security vendors and now a Linux Foundation project. It defines common event classes and field names, so data from different products can be queried the same way.

Where Huntbase fits: Huntbase normalises results to OCSF v1.3, so one rule or query runs on every matching source. Federated SIEM

osquery

An open-source tool, created at Facebook and now a Linux Foundation project, that exposes an operating system as a set of relational tables you can query with SQL: processes, network connections, users, files, installed software and more. It runs on Windows, macOS and Linux.

Where Huntbase fits: Huntbase Endpoint Control is built on open-source osquery. Endpoint Control

Security data lake

Apache Iceberg

Security data kept in low-cost object storage in open formats, queried by separate engines. Apache Iceberg is an open table format that adds schemas, partitions, snapshots and transactions to files in a lake, so several engines can read the same tables safely.

Where Huntbase fits: Huntbase can query your own Iceberg lake, or store telemetry for you. Federated SIEM

Shadow mode

Running a new detection rule against live data and recording what it would have fired on, without alerting anyone. Teams use it to measure noise and accuracy before turning a rule on.

SIEM

Security information and event management

A system that collects logs and events from across an environment, stores them, and lets analysts search, correlate and alert on them. It is often the system of record for security investigations and compliance.

Where Huntbase fits: Huntbase's Federated SIEM queries your existing stores in place, or your own lake. Federated SIEM

Sigma

An open, YAML-based format for describing log detections independently of any one SIEM. A Sigma rule names a log source and the field conditions to match, and tools convert or compile it to a specific query language. The community rule set is maintained by the SigmaHQ project.

Where Huntbase fits: Huntbase compiles Sigma natively and lets you backtest a rule on your own history before it goes live. Sigma rule testing

SOAR

Security orchestration, automation and response

Tools that run security workflows, often called playbooks, across other products: enriching alerts, opening tickets, asking for approval and taking response actions through each tool's API.

SPL

Search Processing Language

Splunk's query language. Searches are written as a pipeline of commands that filter, transform and aggregate indexed events.

STIX

Structured Threat Information Expression

An OASIS standard, currently version 2.1, for representing cyber threat intelligence as JSON objects: indicators, malware, threat actors, campaigns, attack patterns and the relationships between them. STIX patterns describe what to look for in observed data.

Where Huntbase fits: Huntbase translates STIX 2.1 patterns for each connected source. Threat Intelligence

TAXII

Trusted Automated Exchange of Intelligence Information

An OASIS standard protocol for exchanging threat intelligence over HTTPS, usually carrying STIX. Servers expose collections that clients can poll for new objects or publish to.

Threat hunting

The proactive search for attackers who are already inside an environment but have not triggered an alert. Hunters start from a hypothesis, search telemetry and hosts for evidence for or against it, and turn what they learn into better detections.

Where Huntbase fits: Huntbase is built around the hunt: hypothesis, steps, checkpoints and a verdict you record. Threat Hunting

TLP

Traffic Light Protocol

A set of labels, maintained by FIRST, that tells recipients how far they may share information. TLP 2.0 defines TLP:RED, TLP:AMBER+STRICT, TLP:AMBER, TLP:GREEN and TLP:CLEAR.

TTP

Tactics, techniques and procedures

How an adversary operates. Tactics are the goal (for example persistence), techniques are the method (a scheduled task), and procedures are the specific implementation a group uses. Hunting for TTPs is more durable than hunting for IOCs, because behaviour is harder to change than infrastructure.

Two-person approval

Four-eyes principle

A control that requires a second, independent person to approve a sensitive action before it runs. The person who proposed the action cannot approve it themselves.

Where Huntbase fits: In Huntbase, nothing changes on a host until two people sign off (early access). Endpoint Control

XDR

Extended detection and response

Detection and response that correlates telemetry beyond the endpoint, such as identity, email, network and cloud, usually within one vendor's ecosystem or through its integrations.

YARA

An open-source tool and rule language for identifying and classifying files, most often malware, by matching text or byte patterns and conditions. YARA rules are used to scan files on disk, in memory and in malware repositories.

Questions

What is the difference between an IOC and a TTP?

An IOC is an artefact such as a hash, IP address or domain that suggests compromise. A TTP describes how an attacker operates. IOCs are easy to match but cheap for attackers to change; TTPs are harder to change, so hunts built on behaviour last longer.

What is the difference between Sigma and YARA?

Sigma describes detections over log events and is converted to a SIEM's query language. YARA matches patterns in files and memory, most often to identify malware.

How is threat hunting different from detection?

Detection rules wait for known patterns to appear. Threat hunting goes looking for activity that no rule has caught yet, starting from a hypothesis. A good hunt usually ends by turning what it found into a new detection.

Your data.
Your knowledge.
Your call.

Put the terms to work. Sign up and run your first hunt with Scout on your own data, or book a demo.

  1. 01Sign up
  2. 02Run a guided hunt on the sample workspace, no connector needed
  3. 03Connect your own sources when you're ready