<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Méthodologie on CyberVeille</title>
    <link>https://cyberveille.ch/tags/m%C3%A9thodologie/</link>
    <description>Recent content in Méthodologie on CyberVeille</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>fr-fr</language>
    <copyright>Cyberveille CC BY-NC-SA 4.0</copyright>
    <lastBuildDate>Fri, 10 Apr 2026 00:00:00 +0200</lastBuildDate>
    <atom:link href="https://cyberveille.ch/tags/m%C3%A9thodologie/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Unified Threat Hunting Process : méthodologie structurée pour les programmes de threat hunting</title>
      <link>https://cyberveille.ch/posts/2026-04-10-unified-threat-hunting-process-methodologie-structuree-pour-les-programmes-de-threat-hunting/</link>
      <pubDate>Fri, 10 Apr 2026 00:00:00 +0200</pubDate>
      <guid>https://cyberveille.ch/posts/2026-04-10-unified-threat-hunting-process-methodologie-structuree-pour-les-programmes-de-threat-hunting/</guid>
      <description>&lt;h2 id=&#34;-contexte&#34;&gt;🔍 Contexte&lt;/h2&gt;
&lt;p&gt;Publié sur GitHub (sims718718/UnifiedThreatHunting), cet article présente un &lt;strong&gt;Unified Threat Hunting Process&lt;/strong&gt; développé par un Lead Threat Hunter pour construire un programme de threat hunting structuré et reproductible à partir de zéro.&lt;/p&gt;
&lt;h2 id=&#34;-structure-du-processus&#34;&gt;🏗️ Structure du processus&lt;/h2&gt;
&lt;p&gt;Le processus se décompose en &lt;strong&gt;9 étapes séquentielles&lt;/strong&gt; :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Step 0&lt;/strong&gt; : Environment Context (profil SIEM, EDR, type d&amp;rsquo;environnement, vertical métier, rétention des logs)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 1&lt;/strong&gt; : Triggering Event (CTI, incidents passés, red teaming, TTPs MITRE, exigences métier)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 2&lt;/strong&gt; : Hypothesis Development (hypothèse SMART, méthode des hypothèses concurrentes de Heuer)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 3&lt;/strong&gt; : Initial Assessment (sources internes/externes, couverture de détection existante)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 4&lt;/strong&gt; : Feasibility Assessment (décision GO / NO-GO / CONDITIONAL)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 5&lt;/strong&gt; : Define Scope &amp;amp; Objectives&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 6&lt;/strong&gt; : Formalize Hunt Plan (Epics/Stories/Tasks dans Jira)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 7&lt;/strong&gt; : Execute Hunt&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step 8&lt;/strong&gt; : Document Outcomes &amp;amp; Report &amp;amp; Iterate&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;-frameworks-sources&#34;&gt;📚 Frameworks sources&lt;/h2&gt;
&lt;p&gt;Le processus est une synthèse explicite de :&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
