Feb. 19, 2024, 6:18 p.m. | /u/error_therror

cybersecurity www.reddit.com

I'm pretty new in my job as a threat hunter. Whenever we see Hands On Keyboard activity, we escalate it to an IR. As a new guy in my job, something I'm still having trouble doing is determining whether the activity is HOK or just a high alert.

What sort of activity does realtime HOK look like, as opposed to something that happened historically? Any tips on this?

alert cybersecurity doing hands on high high alert hunter job keyboard sort threat

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens