certslothcertsloth
PSOE/Topic 03

Google Cloud / Professional

Threat hunting and retroactive analysis

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Hypothesis, evidence, disproof, refinement.

Must remember

  • Begin with a falsifiable hypothesis, such as a privileged identity being used from a new device before a sensitive export. Choose telemetry that could support or disprove it.
  • Search across identity, endpoint, network and cloud activity; pivot from an indicator to related users, assets, processes and time windows. Logs Explorer, Log Analytics, BigQuery and SecOps serve different data/query contexts.
  • Use GTI, posture findings and incident lessons to prioritize hunts. A low-prevalence process or new domain can be suspicious even without a known malicious hash.
  • Retrohunt applies new intelligence or detection logic to historical events. Confirm the relevant retention, parsed fields and time range exist; a clean result with missing telemetry is inconclusive.
  • Entity risk scores help triage but require evidence and context. Shared infrastructure, scanners and administrator activity can resemble attacks.
  • Record query versions, time bounds, evidence, exclusions and conclusions. Feed validated findings to incident response and reusable detection engineering.

Choose under exam pressure

Requirement Choice and reason
A new IOC is published today Search retained historical telemetry and correlate local context.
No known IOC but suspicious behavior A behavior-based hunt across identity, process and network evidence.

Traps

  • An intelligence match is a lead, not a complete incident verdict.
  • No results cannot establish safety if the source was never collected.

Active recall

1. What makes a good hunt hypothesis?

A specific behavior and conditions that available evidence can confirm or reject.

2. Why pivot beyond one IP?

To identify related entities, scope and alternate attacker infrastructure.

3. What is retrohunt?

Re-evaluating historical telemetry using new indicators or detection logic.

4. How use a risk score responsibly?

As prioritization context alongside source evidence and asset impact.

5. What should a completed hunt produce?

Evidence-based findings, coverage gaps and potential improvements to detections or controls.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.