https://www.sans.org/reading-room/whitepapers/analyst/who-what-where-when-effective-threat-hunting-36785