How do threat hunters become informed and collaborate?
In the continuously evolving cybersecurity landscape, threat hunters play a crucial role in proactively detecting and mitigating security threats. To do this, they need to be well-informed and collaborate effectively.

Threat Hunting in an Evolving Cybersecurity Landscape
In the continuously evolving cybersecurity environment, threat hunters play a crucial role in proactively detecting and mitigating security threats. A recent study conducted by the CHISEL Group at the University of Victoria, available here, sheds light on the practices of threat hunters and their collaboration and information sharing. The report contains several important findings that can help threat hunters and managers develop their strategies.
This is part of my ongoing "Rise of the Threat Hunter" blog series. For more information about the series, please check out the introduction here or read last week's article "Understanding Threat Hunter Personalities."
Collaboration in Threat Hunting
Diverse Collaborators
Threat hunters interact with a wide range of internal and external collaborators. Internally, they closely work with teams such as Security Operations Centers (SOC), data science, and threat intelligence. Externally, they collaborate with customers, cyber insurance companies, supply chain vendors, and other industry connections. Having a diverse network of collaborators enables threat hunters to keep up with new threats, defense tactics, and best practices that enhance everyone's security.
Communication Channels
Effective communication is vital for successful threat hunting. Teams use various platforms like Slack, Microsoft Teams, and email for both synchronous and asynchronous communication. Daily and weekly regular meetings help maintain alignment and ensure timely information sharing. However, the geographical distribution of teams can pose challenges, making it necessary to establish clear communication protocols. A breakdown in communication can lead to missed threats and vulnerable systems, so it's important to plan how communication is handled both synchronously and asynchronously.
Synchronous Collaboration
Synchronous communication enables real-time interaction and quick decision-making. Tools like Slack, Microsoft Teams, and Zoom are crucial in facilitating such real-time communication. Whether it's daily stand-ups, threat intelligence briefings, or ad-hoc problem-solving sessions, regular meetings allow team members to discuss issues, share updates, and align on objectives in real-time.
To maximize synchronous collaboration, establishing clear communication standards is important. This includes setting expectations for response times within working hours, agreeing on communication protocols for different types of information, and using shared documents or dashboards to keep everyone on the same page.
Asynchronous Collaboration
On the other hand, asynchronous communication is very important when working across different time zones or when instant responses are not required. Effectively managing handovers is crucial in this context. For example, when a team member ends their shift, they can leave detailed notes and action items in shared tools like Confluence, Jira, or Trello. This ensures that the next person taking over has all the information they need to continue the work seamlessly.
Many communication tools also offer features that support asynchronous collaboration, such as Slack or Teams' message thread-based discussions, which can be revisited and added to when needed. Documenting decisions, logging important actions, and tagging relevant team members can help inform everyone without requiring real-time interaction.
Teams can maintain momentum by combining synchronous and asynchronous methods, ensuring that critical information is effectively communicated regardless of when or where team members are working.
Improvement Recommendations
The threat hunters in the report recommend automating reporting, reducing the number of meetings, and establishing an official handover protocol to overcome collaboration challenges. Threat hunting is as much a science as it is an art. By eliminating report writing and reducing meetings, threat hunters can gain the time they need to focus on critical, time-consuming tasks. When implemented well, these recommendations can streamline processes and increase efficiency, allowing threat hunters to focus more on their core responsibilities.
Staying Informed About Developments
Core Skills and Learning Strategies
As we all know, threat hunters require a mix of technical and non-technical skills. Technical skills include knowledge about operating systems, network creation, programming, and cybersecurity fundamentals. Non-technical skills such as communication, problem-solving, and analytical abilities are equally important.
Among the technical skills required for threat hunters are knowledge of operating systems, network creation, programming, and cybersecurity fundamentals. Proficiency in scripting languages like Python, Bash, and PowerShell, along with familiarity with command-line interfaces and system management, is very important. Understanding malicious software analysis, digital forensics, and threat environments is also crucial.
These skills can be acquired through formal education (such as computer science or cybersecurity degrees), certifications (like SANS, OSCP, CISSP), and on-the-job training. Practical experience can be gained through capture the flag exercises, hackathons, and simulations. Additionally, staying updated with the latest cybersecurity news, attending webinars, conferences, mentorship programs, and engaging with online communities and resources like GitHub and Stack Overflow are effective strategies for continuous learning.
Non-technical skills include communication, problem-solving, and analytical abilities. Effective communication ensures that complex concepts are clearly conveyed to different audiences, while problem-solving and analytical skills allow threat hunters to investigate issues and develop innovative solutions. These skills can be developed through mentorship, on-the-job training, and self-learning. Participating in team meetings, knowledge-sharing presentations, and conferences also helps in developing these skills. Additionally, reading articles, watching videos, and completing certifications can help threat hunters stay up-to-date with the latest cybersecurity trends and practices.
Information Sources
Threat hunters rely on various information sources, including industry conferences and events, OSINT, GitHub, podcasts, and threat intelligence platforms. I usually learn the most during events like RSA and Black Hat, not necessarily during briefings or presentations but during socializing in the evenings and after conferences when talking to others in the field. Socializing is excellent for getting the most relevant information.
It should not be forgotten that some sources have limitations such as information reliability and paywalls. Finding high-quality data about emerging threats often takes time, which can slow down response times. Integrating important sources into threat hunting tools and verifying the reliability of information sources can help reduce these limitations.
Improvement Recommendations
Threat hunters recommend improving information sources by better integrating them into the main tools of the sources and developing ways to verify the reliability of information. This can help threat hunters stay one step ahead of emerging threats by increasing the reliability and accessibility of critical information. As the industry works on new and better ways to integrate threat intelligence, threat hunters should engage with information sharing and communication within the industry and continue doing so.
Learn More About OpenText Cybersecurity
Ready to empower your threat hunting team with products, services, and training to protect your most valuable and sensitive information? For proactive identification, prioritization, and investigation of anomalous and malicious behavior, explore our comprehensive portfolio of modern complementary security solutions that provide 360-degree visibility across endpoints and network traffic. View our cybersecurity portfolio.
Source: How Threat Hunters Stay Informed and Collaborate - OpenText Blogs