Threat Hunting
Definition
A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been evaded. Distinct from alert triage, which responds to events already flagged by detection systems.
- Field
- Security operations, incident response
- Type
- Proactive, human-led search process
- Assumption
- Automated controls have already been evaded
- Contrast
- Alert triage, which reacts to already-flagged events
Common questions
Why hunt for threats if detection tools are already generating alerts?+
Threat hunting starts from the premise that a skilled adversary can evade signature and rule-based detection entirely, leaving no alert to triage. Hunters proactively form hypotheses about likely attacker behaviour and search raw telemetry for evidence that automated systems never flagged.
What typically triggers a threat hunting exercise?+
Hunts are commonly driven by new threat intelligence about a technique relevant to the organisation's environment, an anomaly noticed during routine review, or a scheduled hypothesis-driven programme, rather than by a specific alert, which distinguishes hunting from reactive SOC work.
Related terms
- Dwell Time
- The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
- Escalation Path
- The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
- Hunting Hypothesis
- A testable statement specifying what adversary behaviour might be present, which data source would show it, and what analytic would surface it....
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Managed Security Service Provider (MSSP)
- A third-party organisation that delivers security monitoring, tooling, and analyst coverage as a contracted service. Used in fully outsourced and co-managed SOC...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Playbook
- A documented step-by-step procedure for responding to a specific type of security event. Playbooks standardise analyst behaviour, reduce response time, and ensure...
- Security Operations Centre (SOC)
- The dedicated team and technology platform responsible for continuous monitoring, detection, analysis, and coordinated response to security events. May be in-house, co-managed,...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
- Tactics, Techniques, and Procedures (TTPs)
- A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
Explained in these topics
- Proactive Threat Hunting Methodology
- SOC Structure and the Tier ModelA proactive activity in which analysts search for indicators of compromise or attacker behaviour that automated detection has not yet flagged. Typically perfor...