Correct answer: 1. Formulate hypothesis. 2. Gather intelligence and data. 3. Investigate patterns and techniques. 4. Automate and enrich.
This is the correct sequence for a structured, hypothesis-driven threat hunt. The process begins by forming a specific hypothesis (e.g., 'An adversary is using PowerShell for lateral movement'). Next, the team gathers relevant intelligence and collects data from sources like EDR, SIEM, and network logs. They then investigate this data to find patterns confirming or denying the hypothesis. Finally, if the hunt is successful, the findings are used to create automated detection rules (enrichment) to catch this activity in the future.