Water-plant hunt finds no known malware hashes on jump hosts, and the hypothesis is that someone disabled logging or added a local admin. Which hunting technique is this?
Select an answer to reveal the explanation.
Short Explanation
This is a settings hunt, not a hash hunt. Configuration hunting looks for insecure or unexpected state: extra services, new local admins, logging turned off on the jump box. No IoC required.
Full Explanation
Configuration hunting examines host and application state for insecure or unexpected settings rather than matching a known indicator. At a water plant, unexpected services, new local administrators, or disabled logging on jump hosts are classic configuration-hunt findings. Indicator hunting would sweep a hash or C2 domain; behavioral analytics would follow an identity's action sequence; modeling would compare volume to a baseline. Absence of a malware hash does not end the hunt when the question is configuration drift.