Backtesting
Running a detection rule or hunt query over historical data to see what it would have found: how often it fires, on which hosts and users, and whether it catches known incidents.
Resources · Glossary
Running a detection rule or hunt query over historical data to see what it would have found: how often it fires, on which hosts and users, and whether it catches known incidents.
Collaborative Automated Course of Action Operations
An OASIS standard for describing security playbooks in a machine-readable, vendor-neutral JSON format, so a course of action can be shared between organisations and run by different tools. Version 2.0 is current.
Where Huntbase fits: Huntbase can export hunt playbooks as CACAO v2. Threat Intelligence
Staged rollout
Releasing a change to a small subset first, watching for problems, then widening it in stages. In security it applies to detection rules, agent updates and response scripts alike.
Common Vulnerability Scoring System
An open standard, maintained by FIRST, for rating the severity of software vulnerabilities on a 0 to 10 scale based on how they can be exploited and what they affect. Version 4.0 was published in 2023.
Where Huntbase fits: Huntbase enriches findings with CVSS, EPSS and KEV in alert triage. AI Alert Triage
The practice of designing, testing, deploying and maintaining detection rules as an engineering discipline: rules live in version control, are tested against real data, are tuned on evidence, and are measured once live.
Where Huntbase fits: Huntbase gives Sigma rules backtests, shadow mode and version history. Detection Engineering
Endpoint detection and response
Software on laptops, servers and workloads that records activity, detects threats and lets responders investigate and contain them, for example by isolating a host or killing a process.
Host containment
Cutting a host off from the network, except for the connection to the security tool managing it, so an attacker cannot use it while responders investigate.
Exploit Prediction Scoring System
A model, maintained by FIRST, that estimates the probability that a published vulnerability will be exploited in the wild in the next 30 days. It complements severity scores by describing likelihood rather than impact.
Querying data in several stores where it lives, instead of first copying it into one central repository. A federated query is sent to each source and the results are combined.
A testable statement that frames a hunt, such as "an attacker is using stolen credentials to sign in from proxy infrastructure". A good hypothesis can be proven wrong, names the data that would confirm or refute it, and is usually drawn from threat intelligence, ATT&CK techniques or something odd an analyst noticed.
A reusable, documented hunt: the hypothesis, the data it needs, the steps and queries, what a positive or negative result means, and its known blind spots.
An open, MIT-licensed format for threat hunt playbooks, published by Huntbase: Markdown with YAML frontmatter, one heading per step and fenced blocks for queries. It reads without tooling and diffs cleanly in version control.
Where Huntbase fits: The spec, examples and tooling are on GitHub. hunt.md spec
Indicator of compromise
An observable artefact that suggests a system has been compromised: a file hash, IP address, domain, URL, registry key or similar. IOCs are easy to share and match, but attackers can change them cheaply, so they age quickly.
CISA Known Exploited Vulnerabilities catalog
A list, maintained by the US Cybersecurity and Infrastructure Security Agency, of vulnerabilities with reliable evidence of exploitation in the wild. US federal agencies must remediate listed vulnerabilities by set deadlines, and many other organisations use it to prioritise patching.
Kusto Query Language
A read-only query language from Microsoft, written as a pipeline of operators. It is used in Azure Data Explorer, Microsoft Sentinel, Microsoft Defender advanced hunting and Azure Monitor.
Where Huntbase fits: Huntbase uses KQL as one query language across every connected store. Federated SIEM
Investigating a running host directly, rather than from logs: listing processes and connections, collecting files and memory, or running scripts. It answers questions the logs never recorded.
Where Huntbase fits: Huntbase Endpoint Control asks hosts live questions mid-hunt. Endpoint Control
An open-source threat intelligence platform for storing, correlating and sharing indicators and events, widely used by CERTs, ISACs and security teams. It began as the Malware Information Sharing Platform.
A public knowledge base, maintained by MITRE, of adversary tactics and techniques observed in real intrusions. It covers enterprise, mobile and industrial control systems, and gives defenders a shared vocabulary for mapping detections, hunts and coverage gaps.
Open Cybersecurity Schema Framework
An open schema for security event data, launched in 2022 by a group of security vendors and now a Linux Foundation project. It defines common event classes and field names, so data from different products can be queried the same way.
Where Huntbase fits: Huntbase normalises results to OCSF v1.3, so one rule or query runs on every matching source. Federated SIEM
An open-source tool, created at Facebook and now a Linux Foundation project, that exposes an operating system as a set of relational tables you can query with SQL: processes, network connections, users, files, installed software and more. It runs on Windows, macOS and Linux.
Where Huntbase fits: Huntbase Endpoint Control is built on open-source osquery. Endpoint Control
Apache Iceberg
Security data kept in low-cost object storage in open formats, queried by separate engines. Apache Iceberg is an open table format that adds schemas, partitions, snapshots and transactions to files in a lake, so several engines can read the same tables safely.
Where Huntbase fits: Huntbase can query your own Iceberg lake, or store telemetry for you. Federated SIEM
Running a new detection rule against live data and recording what it would have fired on, without alerting anyone. Teams use it to measure noise and accuracy before turning a rule on.
Security information and event management
A system that collects logs and events from across an environment, stores them, and lets analysts search, correlate and alert on them. It is often the system of record for security investigations and compliance.
Where Huntbase fits: Huntbase's Federated SIEM queries your existing stores in place, or your own lake. Federated SIEM
An open, YAML-based format for describing log detections independently of any one SIEM. A Sigma rule names a log source and the field conditions to match, and tools convert or compile it to a specific query language. The community rule set is maintained by the SigmaHQ project.
Where Huntbase fits: Huntbase compiles Sigma natively and lets you backtest a rule on your own history before it goes live. Sigma rule testing
Security orchestration, automation and response
Tools that run security workflows, often called playbooks, across other products: enriching alerts, opening tickets, asking for approval and taking response actions through each tool's API.
Search Processing Language
Splunk's query language. Searches are written as a pipeline of commands that filter, transform and aggregate indexed events.
Structured Threat Information Expression
An OASIS standard, currently version 2.1, for representing cyber threat intelligence as JSON objects: indicators, malware, threat actors, campaigns, attack patterns and the relationships between them. STIX patterns describe what to look for in observed data.
Where Huntbase fits: Huntbase translates STIX 2.1 patterns for each connected source. Threat Intelligence
Trusted Automated Exchange of Intelligence Information
An OASIS standard protocol for exchanging threat intelligence over HTTPS, usually carrying STIX. Servers expose collections that clients can poll for new objects or publish to.
The proactive search for attackers who are already inside an environment but have not triggered an alert. Hunters start from a hypothesis, search telemetry and hosts for evidence for or against it, and turn what they learn into better detections.
Where Huntbase fits: Huntbase is built around the hunt: hypothesis, steps, checkpoints and a verdict you record. Threat Hunting
Traffic Light Protocol
A set of labels, maintained by FIRST, that tells recipients how far they may share information. TLP 2.0 defines TLP:RED, TLP:AMBER+STRICT, TLP:AMBER, TLP:GREEN and TLP:CLEAR.
Tactics, techniques and procedures
How an adversary operates. Tactics are the goal (for example persistence), techniques are the method (a scheduled task), and procedures are the specific implementation a group uses. Hunting for TTPs is more durable than hunting for IOCs, because behaviour is harder to change than infrastructure.
Four-eyes principle
A control that requires a second, independent person to approve a sensitive action before it runs. The person who proposed the action cannot approve it themselves.
Where Huntbase fits: In Huntbase, nothing changes on a host until two people sign off (early access). Endpoint Control
Extended detection and response
Detection and response that correlates telemetry beyond the endpoint, such as identity, email, network and cloud, usually within one vendor's ecosystem or through its integrations.
An open-source tool and rule language for identifying and classifying files, most often malware, by matching text or byte patterns and conditions. YARA rules are used to scan files on disk, in memory and in malware repositories.
An IOC is an artefact such as a hash, IP address or domain that suggests compromise. A TTP describes how an attacker operates. IOCs are easy to match but cheap for attackers to change; TTPs are harder to change, so hunts built on behaviour last longer.
Sigma describes detections over log events and is converted to a SIEM's query language. YARA matches patterns in files and memory, most often to identify malware.
Detection rules wait for known patterns to appear. Threat hunting goes looking for activity that no rule has caught yet, starting from a hypothesis. A good hunt usually ends by turning what it found into a new detection.
Put the terms to work. Sign up and run your first hunt with Scout on your own data, or book a demo.