Using Threat Hunting

Item

Description

1

Last Day - Time filter for the query. Users can choose between Last Day, Last 2 Days, Last Week and a Custom time period.

2

Process - Refine your query results according to the activity type.

3

Let the hunt begin - Click + and define the values to search in the logs. You can add multiple values and fields at a time.

4

Menu for predefined queries.

5

Predefined - Check Point's predefined queries, divided by category.

Note:

Leads in Detections, Leads and Alerts are lead detections or signatures. If an incident is raised under this category, the term Lead. is prefixed to its protection name. For example, Lead.Win.BrwsrPassThft.B. It does NOT indicate an attack and we recommend that you ignore these incidents.

This is used by Check Point to analyze if a protection has to be developed. For example, create a new signature.

6

MITRE ATT&CK - Shows the MITRE ATT&CK framework of tactics and techniques. Each technique includes one or more queries, pre-defined by Check Point Research.

7

Bookmarks - Shows the custom queries saved as bookmarks, either as global (available for all users in the account) or private (available only for the user).

Users can also define email notifications for these saved queries, currently limited to 10. For more information, see Saving a Query as a Bookmark.

8

History - See all the queries that you used.

9

Settings - Change the UI look and feel.

To hunt for threats, you can use predefined queries or by proactively creating your own queries.

  • To use predefined queries:

    1. Go to Predefined Hunting Queries or

      Click the icon next to the search box and select Predefined.

      You can quickly find all active attacks and browse through different malicious events detected by Endpoint clients.

    2. Click the icon next to the search box and select MITRE ATT&CK.

      The MITRE ATT&CK dashboard provides real-time visibility on all the techniques observed by Endpoint Security across your endpoints. It maps all raw events to MITRE Tactics, Techniques, and Procedures (TTPs) regardless of status.

      The MITRE ATT&CK dashboard is divided into 12 categories and each category is a stage in an attack. Each category includes multiple attack techniques.

      When you click a technique, a window opens with an explanation about the technique and a list of predefined queries. Run a query to get a list of the events in which the specific technique implementation was used.

  • To search for specific events by proactively creating your own queries:

    1. Go to Threat Hunting.

    2. Click the + sign next to Let the hunt begin.

    3. From the Indicator list, select the filter.

    4. From the Operator list, select the condition.

    5. In the Add a single value field, enter a value for the indicator.

    6. Click Add.

      It shows the search results in a timeline. The timeline provides behavioral insights that indicate anomalies or attacks.

    7. To add another filter to the same query, repeat steps 2 to 6.

      Note:

      If you have multiple filters, the system applies the logical AND operator between the filters.

    8. To filter events based on the timeline, click the required hexagon.

      It shows detailed information about the event, together with intelligent enrichment, such as attack classification, malware family and MITRE technique details.

    9. To create a bookmark for a query, see Saving a Query as a Bookmark.

    10. You can also filter the results by date and process.

    11. To take remediation action for the filtered results, click Actions and choose any of these:

      • Terminate Process

      • Quarantine File

      • Trigger Forensic Analysis

      • Isolate Machine

    12. To export the results to a CSV file, click Actions > Export to CSV.