Threat Hunting is a proactive method to detect hidden adversaries by hypothesis-driven analysis of telemetry and indicators. It combines skilled analysts, detection engineering, and iterative investigation to identify novel threats and reduce dwell time. The method complements automated alerts with human-led discovery and situational context.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Threat hunting proactively searches for signs of attackers or compromised systems before an alert or incident report identifies them clearly.
The approach grew from incident response and military-influenced threat analysis. Knowledge bases such as MITRE ATT&CK organized attacker techniques and supplied a shared frame for searching for their traces.
Form a threat hypothesis, derive observable traces, examine telemetry, validate findings, and then derive countermeasures and further questions.
A testable assumption about possible attacker behavior.
Recorded signals from systems, networks, or applications.
An observation pointing to specific behavior or compromise.
Proactive searching discovers unknown or overlooked activity and strengthens detection against real attack patterns.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.