{"id":31721,"date":"2019-10-31T21:42:43","date_gmt":"2019-10-31T18:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\/"},"modified":"2019-10-31T21:42:43","modified_gmt":"2019-10-31T18:42:43","slug":"threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","title":{"rendered":"Threat Hunting: How to Protect Against 5% of Threats","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>95% of cybersecurity threats are known and can be defended against using traditional means like antivirus software, firewalls, IDS, and WAF. The remaining 5% of threats are unknown and the most dangerous. They account for 70% of the risk to a company because they are very difficult to detect and even harder to defend against. Examples include <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nytimes.com\/2007\/04\/22\/books\/chapters\/0422-1st-tale.html?_r=0\">black swans<\/a><\/noindex> such as the WannaCry and NotPetya\/ExPetr ransomware outbreaks, cryptominers, and the Stuxnet \"cyber weapon\" (which affected Iran's nuclear facilities), along with many others (does anyone still remember Kido\/Conficker?) that are challenging to defend against using classic protection methods. We want to discuss how to combat these 5% of threats using Threat Hunting technology.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/122d450514502e04bd5c9159dc5a5593.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n The continuous evolution of cyberattacks necessitates constant detection and response, ultimately leading us to the idea of an endless arms race between attackers and defenders. Classic defense systems can no longer provide an acceptable level of security where risk doesn't impact key business metrics (economic, political, reputation) without customization for specific infrastructures, but they do cover some risks. Even during the deployment and configuration process, modern protection systems find themselves in a catch-up role and must respond to the challenges of the new era.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/eb1d64ee67c7e36a506f450f6bc36f60.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex>Source<\/noindex><\/p>\n<p>One response to the challenges of modernity for information security specialists may be Threat Hunting technology. The term Threat Hunting (hereafter referred to as TH) emerged a few years ago. The technology itself is quite interesting but still lacks any accepted standards and regulations. The diversity of information sources and the scarcity of Russian-language resources on this topic complicates matters. Therefore, we at 'LANIT-Integration' decided to write an overview of this technology. <\/p>\n<h2>Relevance<\/h2>\n<p>\nThe TH technology relies on infrastructure monitoring processes.<noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/mssp-mdr.html\"> There are two main scenarios for internal monitoring \u2013 Alerting and Hunting.<\/a><\/noindex>Alerting (similar to MSSP services) is a traditional method that involves searching for previously developed signatures and indicators of attacks and responding to them. This scenario is successfully handled by traditional signature-based protection tools. Hunting (an MDR-type service) is a monitoring method that addresses the question, 'Where do signatures and rules come from?'. It is a process of creating correlation rules by analyzing hidden or previously unknown indicators and signs of an attack. Threat Hunting refers to this type of monitoring.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/5e1620075bc3ca68e5f42ed7ed91f730.gif\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nOnly by combining both types of monitoring can we achieve protection that is close to ideal, yet there always remains a certain level of residual risk.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/2b89edcf2141c1ea3ad789908a02819d.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Protection using two types of monitoring<\/i><\/p>\n<p>Here\u2019s why TH (and hunting in general!) will become increasingly relevant:<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/4c27001f933e017550d38672089da08f.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Threats, protection measures, risks.<\/i> <noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">Source<\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">95% of all threats are already well-studied.<\/a><\/noindex>These include types such as spam, DDoS, viruses, rootkits, and other classic malware. Protection against these threats can be implemented with the same classical protection measures.<\/p>\n<p>During any project execution,<noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%97%D0%B0%D0%BA%D0%BE%D0%BD_%D0%9F%D0%B0%D1%80%D0%B5%D1%82%D0%BE\"> 20% of the time is spent on 80% of the work,<\/a><\/noindex>while the remaining 20% of the work takes 80% of the time. Similarly, among the entire threat landscape, 5% of new-type threats will account for 70% of the company's risk. In a company where information security management processes are organized, we can manage 30% of the risk from known threats in one way or another, either by avoiding (eliminating wireless networks altogether), accepting (implementing necessary protection measures), or transferring (for example, to the integrator) that risk. However, protecting against<noindex><a rel=\"nofollow\" href=\"https:\/\/threatpost.ru\/windows-0day-patched-by-third-party\/30640\/\"> zero-day vulnerabilities,<\/a><\/noindex>APT attacks, phishing,<noindex><a rel=\"nofollow\" href=\"https:\/\/www.cloudav.ru\/mediacenter\/news\/business-risks-supply-chain-attacks\/\"> supply chain attacks,<\/a><\/noindex>cyber espionage, and national operations, as well as a large number of other attacks, is much more challenging. The consequences of these 5% of threats will be far more severe (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.group-ib.ru\/brochures\/gib-buhtrap-report.pdf\">the average loss for banks from the buhtrap group is 143 million<\/a><\/noindex>), than the consequences of spam or viruses, against which antivirus software protects.<\/p>\n<p>Everyone is likely to encounter 5% of threats. Recently, we had to install an open-source solution that uses an application from the PEAR (PHP Extension and Application Repository) repository. The attempt to install this application via pear install failed, as<noindex><a rel=\"nofollow\" href=\"http:\/\/pear.php.net\/\"> website<\/a><\/noindex> was unavailable (now there's already a placeholder on it), I had to install it from GitHub. And just recently, it was revealed that PEAR has fallen victim to<noindex><a rel=\"nofollow\" href=\"https:\/\/threatpost.ru\/intruders-modified-pear-installer\/30665\/\"> supply chain attacks<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/8fd5d8332c5f859fa07e4405a1bc3c73.gif\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>We can also recall<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cloud4y\/blog\/338980\/\"> the attack using CCleaner<\/a><\/noindex>, the NePetya ransomware epidemic via the accounting software update module<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cloud4y\/blog\/338980\/\"> M.E.Doc<\/a><\/noindex>. Threats are becoming increasingly sophisticated, and a logical question arises - \"How do we resist these 5% of threats?\"<\/p>\n<h2>Definition of Threat Hunting<\/h2>\n<p>\nSo, Threat Hunting is the proactive and iterative process of seeking and discovering advanced threats that cannot be detected by traditional protective means. Advanced threats include, for example, attacks such as APT, zero-day vulnerability attacks, Living off the Land, and so on.<\/p>\n<p>It can also be rephrased that TH is a process of hypothesis verification. This is predominantly a manual process with elements of automation, in which an analyst, relying on their knowledge and qualifications, sifts through large volumes of information in search of signs of compromise corresponding to an initially defined hypothesis about the presence of a specific threat. A distinctive feature of it is the variety of information sources.<\/p>\n<p>It should be noted that Threat Hunting is not a software or hardware product. It is not alerts that can be seen in some solution. It is not a process of searching for IOCs (indicators of compromise). And it is not some passive activity that goes on without the participation of cybersecurity analysts. Threat Hunting is primarily a process.<\/p>\n<h2>Components of Threat Hunting<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/c80d0ff7d7446b0976013043b48be7c3.gif\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nThe three main components of Threat Hunting: data, technology, people.<\/p>\n<p><b>Data (what?)<\/b>, including Big Data. All kinds of traffic streams, information about previously conducted APTs, analytics, data on user activity, network data, information from employees, information from the dark web, and much more.<\/p>\n<p><b>Technology (how?)<\/b> processing this data - all possible ways to process this data, including Machine Learning.<\/p>\n<p><b>People (who?)<\/b> Those who have extensive experience in analyzing various attacks, developed intuition, and the ability to detect an attack. Typically, these are information security analysts who must be able to generate hypotheses and find confirmation for them. They are the key link in the process.<\/p>\n<h2>The PARIS Model<\/h2>\n<p>\nAdam Bateman<noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/the-paris-model\/\"> describes<\/a><\/noindex> The PARIS model for the ideal TH process. The name hints at a famous landmark in France. This model can be viewed from two perspectives \u2013 top down and bottom up.<\/p>\n<p>In the threat hunting process, moving from the bottom up model, we will deal with numerous pieces of evidence of malicious activity. Each piece of evidence has a measure called confidence \u2013 a characteristic that reflects the weight of this evidence. There are 'concrete', direct proofs of malicious activity, allowing us to quickly reach the top of the pyramid and create an actual alert regarding a confirmed infection. Then there are indirect evidences, the sum of which may also lead us to the top of the pyramid. As always, there is much more indirect evidence than direct, meaning they need sorting and analysis, further research, and ideally this should be automated.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/05de6420a8dec35f0bec3002ee812cdc.gif\" style=\"display:block;margin: 0 auto;\" \/><i>The PARIS Model.<\/i> <noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/the-paris-model\/\">Source<\/a><\/noindex><\/p>\n<p>The top part of the model (1 and 2) is based on automation technologies and various analytics, while the bottom part (3 and 4) relies on qualified people who manage the process. The model can be viewed from the top down, where in the upper blue section we have alerts from traditional protective measures (antivirus, EDR, firewall, signatures) that carry a high degree of confidence and trust, while below are indicators (IOC, URL, MD5, and others) that have a lower degree of confidence and require further investigation. The very bottom and thickest level (4) involves generating hypotheses, creating new scenarios for traditional protective measures. This level is not limited to the specified sources of hypotheses. The lower the level, the more qualifications are required from the analyst.<\/p>\n<p>It is very important for analysts not only to check a final set of predetermined hypotheses, but to constantly work on generating new hypotheses and options for their verification.<\/p>\n<h2>Maturity model of TH usage<\/h2>\n<p>\nIn an ideal world, TH is a continuous process. However, since there is no perfect world, let's analyze<noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/threat-hunting-maturity-model\/\"> the maturity model<\/a><\/noindex> and methods in the context of people, processes, and technologies used. Let's consider the model of the ideal spherical TH. There are 5 levels of utilizing this technology. We will examine them using the evolution of a specific team of analysts as an example.<\/p>\n<p><b>Maturity Levels<\/b><br \/>\n<b>People<\/b><br \/>\n<b>Processes<\/b><br \/>\n<b>Technologies<\/b><\/p>\n<p><b>Level 0<\/b><br \/>\nSOC Analysts<br \/>\n24\/7<br \/>\nTraditional tools:<\/p>\n<p>Traditional<br \/>\nAlert set<br \/>\nPassive monitoring<br \/>\nIDS, AV, Sandboxing,<\/p>\n<p><i>Without TH<\/i><br \/>\nWorking with alerts<\/p>\n<p>signature analysis tools, Threat Intelligence data.<\/p>\n<p><b>Level 1<\/b><br \/>\nSOC Analysts<br \/>\nOne-time TH<br \/>\nEDR<\/p>\n<p>Experimental<br \/>\nBasic knowledge of forensics<br \/>\nIOC Search<br \/>\nPartial coverage of data from network devices<\/p>\n<p><i>Experiments with TH<\/i><br \/>\nGood understanding of networks and application part<\/p>\n<p>Partial application<\/p>\n<p><b>Level 2<\/b><br \/>\nTemporary involvement<br \/>\nSprints<br \/>\nEDR<\/p>\n<p>Periodic<br \/>\nIntermediate knowledge of forensics<br \/>\nA week per month<br \/>\nFull application<\/p>\n<p><i>Temporary TH<\/i><br \/>\nExcellent understanding of networks and application part<br \/>\nRegular TH<br \/>\nFull automation of EDR data usage<\/p>\n<p>Partial use of advanced EDR capabilities<\/p>\n<p><b>Level 3<\/b><br \/>\nDedicated TH team<br \/>\n24\/7<br \/>\nPartial ability to validate TH hypotheses<\/p>\n<p>Preventive<br \/>\nExcellent knowledge of forensics and malware<br \/>\nPreventive TH<br \/>\nFull use of advanced EDR capabilities<\/p>\n<p><i>Specific TH cases<\/i><br \/>\nExcellent knowledge of the attacking side<br \/>\nSpecific TH cases<br \/>\nComplete data coverage from network devices<\/p>\n<p>Configuration tailored to needs<\/p>\n<p><b>Level 4<\/b><br \/>\nDedicated TH team<br \/>\n24\/7<br \/>\nFull ability to validate TH hypotheses<\/p>\n<p>Leading<br \/>\nExcellent knowledge of forensics and malware<br \/>\nPreventive TH<br \/>\nLevel 3, plus:<\/p>\n<p><i>Using TH<\/i><br \/>\nExcellent knowledge of the attacking side<br \/>\nVerification, automation, and validation of TH hypotheses<br \/>\nclose integration of data sources;<\/p>\n<p>Research capability<\/p>\n<p>development tailored to needs and custom use of API.<\/p>\n<p><i>TH maturity levels in the context of people, processes, and technologies<\/i><\/p>\n<p><b>Level 0:<\/b> traditional, without the use of TH. Regular analysts work with a standard set of alerts in passive monitoring mode using standard tools and technologies: IDS, AV, sandboxes, signature analysis tools.<\/p>\n<p><b>Level 1:<\/b> Experimental, using TH. Analysts with basic knowledge of forensics and a good understanding of networks and applied aspects can conduct one-time Threat Hunting by searching for indicators of compromise. The tools include EDR with partial data coverage from network devices. Tools are used partially.<\/p>\n<p><b>Level 2:<\/b> periodic, temporary TH. The same analysts who have already advanced their knowledge in forensics, networks, and applied aspects are tasked with regular engagement (sprint) in Threat Hunting, say, one week a month. The tools include comprehensive data research from network devices, automation of data analysis from EDR, and partial use of EDR's advanced capabilities.<\/p>\n<p><b>Level 3:<\/b> Preventive, frequent TH cases. Our analysts have organized into a dedicated team, acquiring excellent knowledge of forensics and malware, along with understanding the methods and tactics of the attacking side. The process is already being conducted in a 24\/7 mode. The team can partially verify TH hypotheses while fully utilizing the advanced capabilities of EDR with complete data coverage from network devices. Analysts are also capable of configuring tools to suit their needs.<\/p>\n<p><b>Level 4:<\/b> Leading, utilizing TH. The same team has gained the ability to conduct research, generate and automate the process of verifying TH hypotheses. Now, the tools have additional tight integration of data sources, software development tailored to needs, and unconventional use of APIs.<\/p>\n<h2>Threat Hunting Techniques<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/2ce2c8a58773444790a03f7d0c163d76.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Basic Threat Hunting Techniques<\/i><\/p>\n<p>To<noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/Cyber-Threat-Hunting-Data-Science\"> techniques<\/a><\/noindex> TH in order of the maturity of the technology used includes: basic search, statistical analysis, visualization techniques, simple aggregations, machine learning, and Bayesian methods. <\/p>\n<p>The simplest method is basic search, used to narrow down the research area through specific queries. Statistical analysis is applied, for example, to construct a typical user or network activity in the form of a statistical model. Visualization techniques are used for clear representation and simplification of data analysis through graphs and charts, where patterns in the sample are much easier to discern. The technique of simple aggregations on key fields is used to optimize search and analysis. The higher the maturity level achieved in the organization\u2019s Threat Hunting process, the more relevant the use of machine learning algorithms becomes. They are also widely used for spam filtering, malicious traffic detection, and fraud detection. A more advanced type of machine learning algorithms is Bayesian methods, which allow for classification, dimensionality reduction of samples, and topic modeling.<\/p>\n<h2>Diamond Model and Threat Hunting Strategies<\/h2>\n<p>\nSergio Caltagirone, Andrew Pendergast, and Christopher Betz in their work \u201c<noindex><a rel=\"nofollow\" href=\"https:\/\/digital-forensics.sans.org\/summit-archives\/cti_summit2014\/The_Diamond_Model_for_Intrusion_Analysis_A_Primer_Andy_Pendergast.pdf\">The Diamond Model of Intrusion Analysis<\/a><\/noindex>\u201d outlined the key components of any malicious activity and the basic relationships between them.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/2c6c165553be60a836383b1b52cb8987.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Diamond Model for Malicious Activity<\/i><\/p>\n<p>According to this model, there are 4 Threat Hunting strategies that are based on the corresponding key components.<\/p>\n<p>1. Victim-focused strategy. We assume the victim has adversaries, and they will deliver \"opportunities\" via email. We look for enemy data in the email. Searching for links, attachments, etc. We seek confirmation of this hypothesis for a certain period (a month, two weeks), and if nothing is found, the hypothesis is invalid.<\/p>\n<p>2. Infrastructure-focused strategy. There are several methods for employing this strategy. Depending on access and visibility, some are easier than others. For example, we monitor domain name servers known for hosting malicious domains. Or we conduct a process of tracking all new domain registrations for known patterns used by the adversary.<\/p>\n<p>3. Capability-based strategy. In addition to the victim-focused strategy used by most network defenders, there is a capability-based strategy. This is the second most popular and focuses on detecting opportunities presented by the adversary, specifically 'malware' and the potential use of legitimate tools by the adversary, such as psexec, powershell, certutil, and others.<\/p>\n<p>4. Adversary-focused strategy. The adversary-focused approach concentrates on the adversary themselves. This includes the use of publicly available information from open sources (OSINT), gathering data about the adversary, their tactics, techniques, and procedures (TTP), analyzing past incidents, threat intelligence data, and so on.<\/p>\n<h2>Information sources and hypotheses in Threat Hunting<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/d2d586c4e52ee73a45c7eb151298e866.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Some information sources for Threat Hunting<\/i><\/p>\n<p>There can be many information sources. An ideal analyst should be able to extract information from everything around them. Typical sources in almost any infrastructure will include data from security tools: DLP, SIEM, IDS\/IPS, WAF\/FW, EDR. Additionally, various indicators of compromise, Threat Intelligence services, CERT data, and OSINT will also be standard information sources. Information from the darknet can also be leveraged (for instance, there may suddenly be an order for hacking the CEO's email, or a candidate for a network engineer position may have drawn attention through their activities), information received from HR (feedback about candidates from their previous job), and information from security services (such as the results of contractor checks).<\/p>\n<p>However, before utilizing all available sources, at least one hypothesis must be established.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/2169b4ac3393626d1810770c9d107f90.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">Source<\/a><\/noindex><\/p>\n<p>To test hypotheses, they must first be formulated. And to come up with many quality hypotheses, a systematic approach is necessary. The process of generating hypotheses is described in more detail in<noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\"> article<\/a><\/noindex>, this scheme is very convenient to use as the basis for the hypothesis formulation process.<\/p>\n<p>The primary source of hypotheses will be <b>the ATT&amp;CK matrix<\/b> (Adversarial Tactics, Techniques and Common Knowledge). It essentially serves as a knowledge base and a model for assessing the behavior of adversaries carrying out their activities at the latter stages of an attack, usually described using the concept of the Kill Chain. This means during the phases after an attacker has penetrated the internal network of an organization or a mobile device. Initially, the knowledge base included descriptions of 121 tactics and techniques used in attacks, each detailed in a Wiki format. Diverse Threat Intelligence analytics are well-suited as sources for generating hypotheses. Notably, the results of infrastructure analysis and penetration tests stand out \u2013 these are the most valuable data that can provide us with reliable hypotheses due to their foundation on specific infrastructure with its distinct vulnerabilities.<\/p>\n<h2>Hypothesis Verification Process<\/h2>\n<p>\nSergey Soldatov presented<noindex><a rel=\"nofollow\" href=\"http:\/\/reply-to-all.blogspot.com\/2016\/10\/bis-summit.html\"> a good diagram<\/a><\/noindex> with a detailed description of the process; it illustrates the hypothesis verification process in a particular system. I will outline the main stages with brief descriptions.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/62721f0baea687467566949b4d22c4d2.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">Source<\/a><\/noindex> <\/p>\n<p><b>Stage 1: TI Farm<\/b><\/p>\n<p>At this stage, it is necessary to identify <b>objects<\/b> (by analyzing them along with all threat data) and assign them labels indicating their characteristics. This can be a file, URL, MD5, process, utility, or event. By passing them through Threat Intelligence systems, labels need to be applied. For instance, this site was noted in CNC in a certain year, this MD5 was linked to a specific malware, this MD5 was downloaded from a site that distributed malware.<\/p>\n<p><b>Stage 2: Cases<\/b><\/p>\n<p>In the second stage, we examine the interactions between these objects and identify relationships among all of them. We obtain marked systems that are performing suspicious activities.<\/p>\n<p><b>Stage 3: Analyst<\/b><\/p>\n<p>In the third stage, the case is handed over to an experienced analyst who possesses extensive analysis expertise, and he delivers the verdict. He breaks down the code byte by byte to determine what, where, how, why, and the purpose behind it. This body was malicious, this computer was infected. He uncovers links between objects and verifies the results through the sandbox.<\/p>\n<p>The analyst's findings are passed on. Digital Forensics investigates images, Malware Analysis examines discovered artifacts, and the Incident Response team may deploy to the location to investigate something on-site. The outcome will be a confirmed hypothesis, identified attack, and counteraction strategies.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting: How to Protect Against 5% of Threats\" src=\"\/wp-content\/uploads\/2019\/04\/94dcee9918011a6f7c32551c09a6e600.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/megane_wakui\/22066181186\/\">Source<\/a><\/noindex><br \/>\n \u00a0<\/p>\n<h2>Summary<\/h2>\n<p>\nThreat Hunting is a relatively new technology capable of effectively countering customized, novel, and unconventional threats, which has significant potential given the increasing number of such threats and the complexity of corporate infrastructure. It requires three components: data, tools, and analysts. The benefits of Threat Hunting extend beyond preempting threats. It's important to remember that during the search process, we delve into our infrastructure and its weak points through the eyes of a security analyst and can further strengthen those areas.<\/p>\n<p>The first steps that, in our opinion, should be taken to initiate the Threat Hunting process within your organization.<\/p>\n<ol>\n<li>Ensure the protection of endpoints and network infrastructure. Ensure visibility (NetFlow) and control (firewall, IDS, IPS, DLP) of all processes in your network. Know your network from the edge router to the very last host.<\/li>\n<li>Study<noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/\"> MITRE ATT&amp;CK<\/a><\/noindex>.<\/li>\n<li>Conduct regular penetration tests on at least the key external resources, analyze the results, identify the main targets for attacks, and close their vulnerabilities.<\/li>\n<li>Implement an open-source Threat Intelligence system (e.g., MISP, Yeti) and conduct log analysis alongside it.<\/li>\n<li>Implement an Incident Response Platform (IRP): R-Vision IRP, The Hive, a sandbox for analyzing suspicious files (FortiSandbox, Cuckoo).<\/li>\n<li>Automate routine processes. Log analysis, incident creation, notifying staff \u2014 these are vast areas for automation.<\/li>\n<li>Learn to interact effectively with engineers, developers, and technical support for collaborative work on incidents.<\/li>\n<li>Document the entire process, key points, and results achieved, so you can refer back to them later or share this information with colleagues;<\/li>\n<li>Remember the social aspect: stay informed about what is happening with your employees, who you hire, and who you grant access to the organization's information resources.<\/li>\n<li>Stay informed about trends in new threats and ways to protect against them, enhance your level of technical literacy (including in the operation of IT services and subsystems), attend conferences, and communicate with colleagues.<\/li>\n<\/ol>\n<p>\nI am ready to discuss the organization of the TH process in the comments.<\/p>\n<p><b class=\"spoiler_title\">Or come work with us!<\/b><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-31.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Lead Cybersecurity Consultant<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-163.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Information Security System Architect<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-4.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Lead Network Security Engineer<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-136.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Lead Information Security Engineer (SIEM)<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-100.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Cybersecurity Architect (Applied)<\/a><\/noindex><\/li>\n<\/ul>\n<p>\n<b class=\"spoiler_title\">Sources and Materials for Study<\/b><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/\">threathunter.guru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/\">attack.mitre.org<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/digital-forensics.sans.org\/summit-archives\/cti_summit2014\/The_Diamond_Model_for_Intrusion_Analysis_A_Primer_Andy_Pendergast.pdf\">digital-forensics.sans.org<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/resources.infosecinstitute.com\/category\/enterprise\/threat-hunting\/\">resources.infosecinstitute.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.redcanary.com\/blog\/threat-hunting-not-a-magical-unicorn\/\">www.redcanary.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/blog-the-eight-steps-to-threat-hunting\">www.cybereason.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">www.anti-malware.ru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/Cyber-Threat-Hunting-Data-Science\">www.anti-malware.ru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"http:\/\/reply-to-all.blogspot.com\/2016\/10\/bis-summit.html\">reply-to-all.blogspot.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">lukatsky.blogspot.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/whitepapers.theregister.co.uk\/paper\/view\/6965\/threat-hunting-for-dummies\">whitepapers.theregister.co.uk<\/a><\/noindex><\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/lanit\/blog\/447580\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435. \u041e\u043d\u0438 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 70% \u0440\u0438\u0441\u043a\u0430 \u0434\u043b\u044f \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0432 \u0441\u0438\u043b\u0443 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u043e\u0447\u0435\u043d\u044c \u043d\u0435\u043f\u0440\u043e\u0441\u0442\u043e \u0438\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0442\u044c \u0438 \u0443\u0436 \u0442\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f. \u041f\u0440\u0438\u043c\u0435\u0440\u0430\u043c\u0438 \u00ab\u0447\u0435\u0440\u043d\u044b\u0445 \u043b\u0435\u0431\u0435\u0434\u0435\u0439\u00bb \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u044d\u043f\u0438\u0434\u0435\u043c\u0438\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a\u043e\u0432 WannaCry, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23622,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31721","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Threat Hunting, \u0438\u043b\u0438 \u041a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 5% \u0443\u0433\u0440\u043e\u0437 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Threat Hunting, or How to Protect Against 5% of Threats | ProHoster","description":"95% of information security threats are known, and you can defend against them using traditional means like antivirus software, firewalls, IDS, and WAF. The other 5% of threats are unknown and the most dangerous.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Threat Hunting, \u0438\u043b\u0438 \u041a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 5% \u0443\u0433\u0440\u043e\u0437 | ProHoster","og:description":"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:42:43+00:00","article:modified_time":"2019-10-31T18:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31721","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 07:30:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:12:32","updated":"2026-01-21 07:30:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31721"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31721\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/23622"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}