H3AD-REF / REFERENCES / DEFENSIVE & HUNTING MATURITY MODELS

How Mature Is the Program, Actually.
And How Do You Measure It.

Sliding Scale of Cyber Security shows where investment goes as a program matures. SOC Visibility Triad shows what data actually backs it. PEAK and the Hunting Maturity Model grade the hunt practice itself — from ad-hoc alerting to a program that turns its own findings into standing detections.

PART OF A 4-FILE SERIES ON SECURITY FRAMEWORKS & MODELS Attack Lifecycle & Adversary Models · Incident Response & Analysis Models · Defensive & Hunting Maturity Models · Threat Intel Cycles

Sliding Scale of Cyber Security

Robert M. Lee, SANS. Five categories of security investment, left to right. Most orgs live entirely in the first two.

01
ARCHITECTURE
Secure design: segmentation, hardening
›
02
PASSIVE DEFENSE
Defends without a human: IDS/IPS, firewalls
›
03
ACTIVE DEFENSE
Analyst-driven monitoring, threat hunting
›
04
INTELLIGENCE
Collect and analyze adversary data to decide
›
05
OFFENSE
Legal countermeasures — nation-state/LE only
INCREASING COST, SKILL, AND LEGAL AUTHORITY REQUIRED →

SOC Visibility Triad

Gartner / Anton Chuvakin. Three data sources, none of which sees everything alone — a SOC built on just one has a permanent blind spot.

NETWORK

NDR

Network Detection & Response
Sees traffic an endpoint agent can't: unmanaged devices, IoT, encrypted-metadata patterns, east-west lateral movement between hosts with no agent on either end.
ENDPOINT

EDR

Endpoint Detection & Response
Sees what the wire can't: process trees, command lines, in-memory injection, and file activity — the ground truth for what actually executed.
CENTRAL

SIEM / Log Management

Correlates the other two, plus everything else
The only point that sees identity, cloud, application, and auth logs alongside NDR and EDR telemetry — where cross-source correlation and long-term retention actually happen.

PEAK Threat Hunting Framework

Splunk / David Bianco. Three stages, three hunt types underneath them: hypothesis-driven, baseline (EDA), and model-assisted (M-ATH).

01
PREPARE
Pick a topic, research it, scope the hunt
›
02
EXECUTE
Dig into the data, test the hypothesis
›
03
ACT WITH KNOWLEDGE
Document, automate the finding, communicate it

Hunting Maturity Model

David Bianco, 2015. Scored on three inputs — data collection, data access, and the hunters' own analysis skill — reduced to a single HMM number.

0
INITIAL
Mostly automated alerting, little to no hunting
›
1
MINIMAL
Follows external threat intel, procedural at best
›
2
PROCEDURAL
Runs published hunting procedures from others
›
3
INNOVATIVE
Builds its own hunting procedures, strong data access
›
4
LEADING
Automates successful hunts into standing detections
HM0 → HM4 — MOST ORGS TOP OUT AROUND HM2 WITHOUT DEDICATED HUNT HEADCOUNT
RELATED

TaHiTI

Targeted Hunting integrating Threat Intelligence
A hunting-process framework from a Dutch financial-sector consortium, built on top of the Hunting Maturity Model above. Adds a third hunt trigger — the unstructured / data-driven hunt — alongside intel-driven and situational-awareness hunts, plus formal hunt-abstract and evaluation documentation.