SPLK-5001 · Question #66
A threat hunter executed a hunt based on the following hypothesis: As an actor, I want to plant rundll32 for proxy execution of malicious code and leverage Cobalt Strike for Command and Control…
The correct answer is D. The threat hunt was successful in providing strong evidence that the tactic and tool is not present. Option D is correct because a threat hunt's success is measured by the quality and confidence of its conclusion, not by whether malicious activity was discovered. The hunter used multiple corroborating data sources (Sysmon, netflow, IDS, EDR) and reached a confident conclusion…
Question
A threat hunter executed a hunt based on the following hypothesis:
As an actor, I want to plant rundll32 for proxy execution of malicious code and leverage Cobalt Strike for Command and Control. Relevant logs and artifacts such as Sysmon, netflow, IDS alerts, and EDR logs were searched, and the hunter is confident in the conclusion that Cobalt Strike is not present in the company's environment. Which of the following best describes the outcome of this threat hunt?
Options
- AThe threat hunt was successful because the hypothesis was not proven.
- BThe threat hunt failed because the hypothesis was not proven.
- CThe threat hunt failed because no malicious activity was identified.
- DThe threat hunt was successful in providing strong evidence that the tactic and tool is not present
How the community answered
(48 responses)- A6% (3)
- B2% (1)
- C13% (6)
- D79% (38)
Explanation
Option D is correct because a threat hunt's success is measured by the quality and confidence of its conclusion, not by whether malicious activity was discovered. The hunter used multiple corroborating data sources (Sysmon, netflow, IDS, EDR) and reached a confident conclusion - that is exactly what a well-executed hunt delivers. Providing strong evidence that a threat is absent is a legitimate and valuable outcome that reduces uncertainty and informs defensive posture.
Why the distractors fail:
- A gets the outcome right (successful) but gives a misleading reason - "hypothesis not proven" sounds like a logic error; the real reason is the confidence and rigor of the investigation.
- B wrongly equates "hypothesis not proven" with failure - in threat hunting, a negative finding after thorough investigation is still success.
- C applies a forensic/IR mindset to a hunting context - IR might "fail" without finding something, but threat hunting succeeds when it answers its hypothesis either way.
Memory tip: Think of threat hunting like a doctor ordering a chest X-ray to rule out pneumonia. If the X-ray is clean and the doctor is confident, that's a successful diagnostic process - not a failed one. A hunt that confidently rules out a threat is doing its job.
Topics
Community Discussion
No community discussion yet for this question.