There is a big gap between what attackers do and what preventions defenders do to prevent it. The general idea is to build bigger and better blacklists for all the threats known or calculated using better threat intelligence.  We always hunt for easy ways, trying to seek out automation of security infrastructure. But these won't' suffice. The reason is because all the defenses are static and accessible to all. All it takes a hacker is to write a script to bypass these security measures. So a possible solution might be RITA, which stands for Real Intelligence Threat Analysis. Its SANS's free new framework that will help in hunting attackers by extending the traditional signature analysis. Read more at: http://www.darkreading.com/vulnerabilities---threats/introducing-rita-for-real-intelligence-threat-analysis/a/d-id/1323244