A mature SOC notices that several incidents over the past year involved attackers abusing legitimate
administrative tools rather than deploying custom malware. Leadership asks the threat hunting team to
improve detection coverage in a way that increases attacker cost rather than relying on easily replaceable
indicators. Which detection strategy best aligns with this objective?
A SOC team using Cisco security technologies wants to improve its ability to detect threats that bypass
traditional security controls by abusing valid user credentials. Which hunting focus MOST effectively
addresses this challenge?