A proactive, hypothesis-driven process to detect hidden adversaries within environments, reducing dwell time and improving detection through iterative investigation and telemetry analysis.
Threat Hunting is a proactive method to detect hidden adversaries by hypothesis-driven analysis of telemetry and indicators. It combines skilled analysts, detection engineering, and iterative investigation to identify novel threats and reduce dwell time. The method complements automated alerts with human-led discovery and situational context.
Average time between compromise and detection.
Proportion of newly identified tactics and techniques per period.
Share of hunting findings that turn out to be non-malicious.
Case where the hunting team discovered unusual authentication attempts and prevented lateral movement.
Example of iterative rule improvement based on hunting findings and telemetry tests.
Rapid hypothesis formation and historical log search for new IoCs.
Identify visibility gaps and prioritize telemetry sources
Create hunt playbooks and hypothesis templates
Integrate tooling (SIEM, EDR, search)
Conduct pilot hunts and validate findings
Operationalize: rules, dashboards and escalation paths