In the Threat Hunting Maturity Model (HMM), Level 2: Procedural represents an organization that has developed a structured but partially manual threat-hunting capability.
At this stage, organizations:
Use threat intelligence from open and closed sources to guide hunts.
Search for anomalies or suspicious activity across their network.
Employ open-source tools and basic scripts for analysis.
Depend on analysts following documented procedures rather than automated systems.
Why the Other Options Are Incorrect:
Level 1: Minimal: Organization relies solely on reactive security measures and lacks dedicated hunting capabilities.
Level 3: Innovative: Introduces automation and advanced analytics to support hunts.
Level 4: Leading: Represents full maturity with proactive, automated, intelligence-driven hunting integrated across all defenses.
Conclusion:
The organization described is operating at Level 2: Procedural in the Threat Hunting Maturity Model.
Final Answer: A. Level 2: Procedural
Explanation Reference (Based on CTIA Study Concepts):
According to CTIA’s framework on “Threat Hunting Maturity Levels,” Level 2 involves intelligence-driven, manual hunting using open-source tools and structured procedures.
Submit