What is the main difference between hypothesis-driven and data-driven Threat Hunting?
Data-driven hunts always require more data to search through than hypothesis-driven hunts.
Data-driven hunting tries to uncover activity within an existing data set, hypothesis-driven hunting begins with a potential activity that the hunter thinks may be happening.
Hypothesis-driven hunts are typically executed on newly ingested data sources, while data-driven hunts are not.
Hypothesis-driven hunting tries to uncover activity within an existing data set, data-driven hunting begins with an activity that the hunter thinks may be happening.
Could someone please verify the accuracy of this answer