Threat Hunting
Look beyond conventional alerts to investigate suspicious behaviors, patterns and potential threats.
Alerts only fire for activity someone anticipated. Threat hunting starts from the opposite assumption: that something may be present which no current rule describes, and goes looking for it deliberately.
It is structured work, not browsing logs. A hunt begins with a hypothesis specific enough to be wrong — and a hunt that finds nothing still produces something useful, because it either raises confidence or exposes a gap in what you can see.
A hunt is a loop, and its most common output is a better detection rule.
- HYPOTHESISHypothesisA specific, testable statement about behaviour that might be present
- DATADataIdentify which sources could confirm or rule it out
- QUERYQueryInterrogate the data for the pattern in question
- ANALYSISAnalysisSeparate expected activity from what genuinely stands out
- VALIDATIONValidationEstablish whether what stands out is benign or real
- IMPROVEMENTDetection improvementTurn the result into detection logic or a visibility fix
Conceptual methodology. Data sources available for hunting depend on what is collected and retained.
You cannot alert on what you never modelled
Detection logic encodes known behaviour. That makes it efficient and it makes it blind in a predictable way: activity that resembles legitimate use, or that nobody thought to describe, produces no alert at all.
Silence is therefore ambiguous. It can mean nothing is happening, or that nothing is watching for it. Hunting is how that ambiguity gets tested rather than assumed.
What are we looking for?
Categories of behaviour we investigate, described at a level useful for scoping. Findings are documented privately to your team.
Focus areas
When Is It Worth Looking Beyond the Alerts?
Output your team can act on.
Which of these apply depends on engagement scope.
A clearer view of what activity is happening across the environment in scope.
What the monitored signals show over time, and what changed.
Activity identified as worth attention, with the reasoning behind it.
What was examined, what it indicated and what was ruled out.
A written account of an incident: timeline, impact and actions taken.
Recommended actions, and where a decision needs to sit with your team.
Where detection, logging or process could be strengthened.
The rest of the operations lifecycle.
Questions we get asked before an engagement.
Monitoring reacts to conditions defined in advance. Hunting starts from a hypothesis and goes looking, which is what allows it to surface activity no existing rule describes.
That is a normal and useful outcome. A hunt that finds nothing either increases confidence in an area or shows that the data needed to answer the question was not being collected — and the second result is often the more valuable one.
It depends on the hypothesis. Endpoint, authentication, network and cloud activity logs are the common sources. Retention matters as much as coverage: a hunt can only look as far back as the data goes.
Periodically, and after events that change the picture — a migration, an acquisition, a relevant threat report, or an incident elsewhere in your sector. Continuous hunting is less useful than well-timed hunting with a clear question.
Explore Threat Hunting
Bring us a question you have not been able to answer from your alerts. That is usually the right place for a hunt to start.
