Fuzzy to Clear: Elucidating the Threat Hunter Cognitive Process and Cognitive Support Needs
Alessandra Maciel Paz Milani, Arty Starr, Samantha Hill, Callum Curtis, Norman Anderson, David Moreno-Lumbreras, Margaret-Anne Storey

TL;DR
This study explores the cognitive processes of threat hunters through observational research, aiming to improve tool support and enhance cybersecurity practices by focusing on human factors.
Contribution
It introduces a model of threat hunter cognition, identifies key support needs, and proposes design improvements for cybersecurity tools based on empirical insights.
Findings
Threat hunters develop and refine mental models during sessions.
23 themes reveal critical support needs for threat hunters.
Five design propositions to improve threat hunting tools.
Abstract
With security threats increasing in frequency and severity, it is critical that we consider the important role of threat hunters. These highly-trained security professionals learn to see, identify, and intercept security threats. Many recent works and existing tools in cybersecurity are focused on automating the threat hunting process, often overlooking the critical human element. Our study shifts this paradigm by emphasizing a human-centered approach to understanding the lived experiences of threat hunters. By observing threat hunters during hunting sessions and analyzing the rich insights they provide, we seek to advance the understanding of their cognitive processes and the tool support they need. Through an in-depth observational study of threat hunters, we introduce a model of how they build and refine their mental models during threat hunting sessions. We also present 23 themes…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDeath Anxiety and Social Exclusion
