Skip to content
Talk to a Security Expert
DEFENSIVE SECURITY / PROACTIVE INVESTIGATION

Threat Hunting

Look beyond conventional alerts to investigate suspicious behaviors, patterns and potential threats.

Alerts only fire for activity someone anticipated. Threat hunting starts from the opposite assumption: that something may be present which no current rule describes, and goes looking for it deliberately.

It is structured work, not browsing logs. A hunt begins with a hypothesis specific enough to be wrong — and a hunt that finds nothing still produces something useful, because it either raises confidence or exposes a gap in what you can see.

Hypothesis-driven hunting

A hunt is a loop, and its most common output is a better detection rule.

  1. HYPOTHESISHypothesisA specific, testable statement about behaviour that might be present
  2. DATADataIdentify which sources could confirm or rule it out
  3. QUERYQueryInterrogate the data for the pattern in question
  4. ANALYSISAnalysisSeparate expected activity from what genuinely stands out
  5. VALIDATIONValidationEstablish whether what stands out is benign or real
  6. IMPROVEMENTDetection improvementTurn the result into detection logic or a visibility fix

Conceptual methodology. Data sources available for hunting depend on what is collected and retained.

// CONTEXT

You cannot alert on what you never modelled

Detection logic encodes known behaviour. That makes it efficient and it makes it blind in a predictable way: activity that resembles legitimate use, or that nobody thought to describe, produces no alert at all.

Silence is therefore ambiguous. It can mean nothing is happening, or that nothing is watching for it. Hunting is how that ambiguity gets tested rather than assumed.

// WHAT WE LOOK FOR

What are we looking for?

Categories of behaviour we investigate, described at a level useful for scoping. Findings are documented privately to your team.

// CAPABILITIES

Focus areas

// WHEN THIS APPLIES

When Is It Worth Looking Beyond the Alerts?

01SITUATIONQuiet environment, low confidenceFew alerts, and no way to tell whether that is good news.
02SITUATIONAfter a nearby incidentA peer or supplier was affected and you want to check for similar activity.
03SITUATIONDetection coverage reviewEstablishing what current logic would and would not catch.
04SITUATIONNew environment inheritedA migration or acquisition brought systems with unknown history.
// WHAT YOU RECEIVE

Output your team can act on.

Which of these apply depends on engagement scope.

SECURITY VISIBILITY

A clearer view of what activity is happening across the environment in scope.

MONITORING INSIGHTS

What the monitored signals show over time, and what changed.

DETECTION FINDINGS

Activity identified as worth attention, with the reasoning behind it.

INVESTIGATION CONTEXT

What was examined, what it indicated and what was ruled out.

INCIDENT REPORTING

A written account of an incident: timeline, impact and actions taken.

RESPONSE GUIDANCE

Recommended actions, and where a decision needs to sit with your team.

SECURITY IMPROVEMENT RECOMMENDATIONS

Where detection, logging or process could be strengthened.

// FREQUENTLY ASKED

Questions we get asked before an engagement.

Explore Threat Hunting

Bring us a question you have not been able to answer from your alerts. That is usually the right place for a hunt to start.