CrowdStrike’s Falcon OverWatch threat hunting report reveals a record 50% year-over-year increase in hands-on cyberattack attempts — and distinct changes in related trends and adversary tactics.
The fourth annual report, Nowhere to Hide: 2022 Falcon OverWatch Threat Hunting Report, examines global threat hunting operations from July 1, 2021 through June 30, 2022. The report offers in-depth attack data and analysis, case studies and actionable recommendations.
CrowdStrike, an endpoint protection platform provider, identified more than 77,000 potential intrusions — approximately one every seven minutes. These are instances where proactive, human-led threat hunting uncovered adversaries actively carrying out malicious techniques at various stages of the attack chain, despite attackers’ best efforts to covertly evade autonomous detection methods, the report states.
Breakout Time Falls
The report examines the time, on average, it takes an adversary to move laterally from initial compromise to other hosts within the victim environment. In fact, the “breakout” time fell to one hour and 24 minutes, compared to one hour and 38 minutes as reported in the 2022 CrowdStrike Global Threat Report.
Falcon OverWatch found that in 30% of cybercrime incidents, the threat actor was able to move laterally in under 30 minutes. These findings, says Falcon OverWatch, underline the speed and scale at which threat actors evolve their tactics, techniques and procedures (TTPs). Correspondingly, they are capable of bypassing even the most sophisticated technology-based defense systems to successfully achieve their goals, the report states.
Param Singh, vice president of Falcon OverWatch at CrowdStrike, put the report findings into perspective:
“Over the past 12 months, the world has faced new challenges spurred by economic pressures and geopolitical tensions, backdropping a threat landscape that is as complicated as ever. To thwart brazen threat actors, security teams must implement solutions that proactively search for hidden and advanced attacks every hour of every day.”
Top Attack Targets Identified
Other key findings from the report include: