MITRE CASCADE analytics
cascade → automated hunts
Executes CASCADE (MITRE) automated analytics, launching predefined hunts over the data to find suspicious activity.
Use it when you want automated hunting with the MITRE reference: CASCADE (Cyber Analytics and SCADA Analysis Development Environment) defines detection analytics with hunt steps and automation — the analytic runs over the data (logs) and the result is the set of suspicious events to review. It's hunting as code: the documented analytic (behavior, detection step) executed repeatably. In purple teaming and hunting, CASCADE is the analytics methodology: the hunt of a technique defined and automated — proactive detection of attacker behaviors.
Don't use it without data: analytics run over sources (SIEM logs) — without centralized data, the hunt has no material. And note: the CASCADE ecosystem is reference (the MITRE project, with methodology more than a deployable product): analytics adapt to the environment (SIEM queries) — full automation requires the environment's pipeline (saved searches, alerts). CASCADE analytics are the hunt design, SIEM implementation is the team's. Hunt results are reviewed with context — the analytic flags, the analyst decides.