In the Packet Forensic Files, Episode 66, Michael talks to Corelight’s Cody Spooner.
By Michael Morris, Senior Director of Global Business Development, Endace
![]()
The Increasing Complexity of Incident Response
and Threat Hunting
In this episode of the Endace Packet Forensic Files, I sat down with Cody Spooner, Principal Sales Engineer and DFIR expert at Corelight, to discuss a really interesting topic: the subtleties and differences of “Enablers” vs “Behaviors” of a cybersecurity compromise.
Cody explains that when most people think of threat hunting or incident response investigations, they picture analysts looking for signs of malicious activity. In reality there are critical subtle differences between the “behavior of a compromise” and the underlying “enabler of a compromise” that often go unnoticed or overlooked. He highlights how organizations tend to focus heavily on detecting malicious behaviors – such as data exfiltration or unauthorized logins – but often miss identifying the enabling conditions – such as misconfigurations or legacy protocols – that led to those compromises in the first place.
Cody shares examples of seemingly harmless issues that can become the doorway to a full compromise, such as configuration issues or outdated or deprecated protocols like NTLMv1 and SMBv1. These often persist in modern environments and Cody suggests that incident responders and threat hunters can usefully focus on identifying and eliminating these enablers to reduce the organisation’s risk profile.
Cody gives advice for security teams on how to shift their mindset from focusing only on behaviors to focusing on enablers as well in their threat hunting activity. He also provides insights into how IR teams should interpret and contextualize indicators of compromise and discusses how the “why” behind an attack can often change or influence the response strategy.
Finally, Cody shares his thoughts on what emerging technologies or architectural trends will create new classes of enablers that defenders need to start paying attention to now.
Other episodes in the Secure Networks video/audio podcast series are available here. Or listen to the podcast here or on your favorite podcast platform.