DefinitionThreat hunting is the proactive, analyst-led search for signs of attackers who are already in the environment and have gone unnoticed by detection tools. It starts from hypotheses about adversary behavior instead of waiting for an alert.
How it works
Threat hunting starts from the premise that some compromise may have slipped past automated rules. The analyst forms a hypothesis, looks for evidence in the telemetry and concludes whether the activity is malicious, benign, or whether there is not enough data to answer.
Hypotheses usually come from three sources:
- Threat intelligence: campaigns and groups active in the sector, with their known techniques.
- Attack techniques: behaviors described in MITRE ATT&CK, such as misuse of legitimate administrative tools or persistence through scheduled tasks.
- Environment anomalies: deviations from the normal baseline, such as a service account logging in interactively or an unusual volume of data leaving the network.
The raw material is the telemetry already collected by EDR, SIEM, NDR and identity and cloud logs. Without data with good retention and detail, hunting is limited.
Threat hunting vs alert monitoring
Traditional monitoring is reactive: a rule fires and the analyst investigates. Threat hunting reverses the order and looks for what no rule caught. Searching for indicators of compromise, such as hashes and IP addresses, is useful, but attackers change them easily. Hunting for behavior, that is, tactics, techniques and procedures, produces more durable results.
In practice
Every hunt should produce a concrete outcome, even when nothing is found: a new detection rule, a log source that needs to be enabled, or documented confirmation that the technique is covered. This cycle is what makes hunting improve the SOC over time instead of being an isolated activity.
Network Secure operates a 24×7 SOC, with MDR, certified to ISO/IEC 27001:2022.
Frequently asked questions
What is the difference between threat hunting and threat intelligence?
Threat intelligence is information about adversaries, campaigns and techniques. Threat hunting is the activity of searching for those behaviors in your own environment. Intelligence feeds the hunting hypotheses.
Does threat hunting replace detection tools?
No. Hunting depends on the telemetry collected by EDR, SIEM and NDR and is used to find what automated rules missed, turning findings into new detections.