Proactive threat hunting
Hunting starts from the assumption that the alerts did not fire. If your detection was going to catch it, you would not need to go looking.
What hunting actually is
Monitoring waits for a rule to match. Hunting assumes the rules are incomplete and goes looking anyway, which is a reasonable assumption given that detection is built from attacks people already understood.
Done properly it is not browsing dashboards. Each hunt starts from a stated hypothesis, defines what evidence would confirm or rule it out, and ends with an answer either way. A hunt that finds nothing is still a result: it tells you that a specific technique is not present, and how well you could have seen it if it were.
How a hunt runs
Hypothesis
A specific, testable statement. Not "look for ransomware" but "an attacker is using a legitimate remote access tool to maintain access, because that is what is being used against organisations in this sector and it would not trigger our current rules".
Data and search
We establish what telemetry would show that behaviour, confirm it is actually being collected, and then search it. This step regularly produces the first finding of the engagement, because the data needed to detect a technique is frequently not being retained at all.
Triage and outcome
Anything anomalous is run down to a conclusion: benign and explained, misconfiguration, risky practice, or genuine adversary activity. We do not hand over a list of oddities for someone else to interpret.
Detection engineering
Every hunt that could be automated becomes a rule, so the same hypothesis does not need hunting again. This is the compounding part, and the reason hunting is worth doing repeatedly rather than once.
What we hunt for
Hypotheses are drawn from techniques currently being used against organisations like yours, from the gaps we find in your own detection coverage, and from the things that are quietly common regardless of sector: legitimate administrative tooling used by someone who should not have it, persistence in scheduled tasks and start-up locations, identity activity that makes no sense for the person it belongs to, mail rules that silently forward or delete, and consented applications nobody remembers approving.
What you need for it to work
Hunting needs data with enough history to look back through. Endpoint telemetry, authentication and identity logs, and network or proxy records are the useful minimum, with ninety days of retention as a sensible floor. Where the retention is not there, that finding comes first, because no amount of skill recovers evidence that was never kept.
What you get
A written record of each hypothesis and its outcome, anything found and what was done about it, the detections built as a result, and an honest statement of where your visibility is too thin for a hunt to be meaningful. That last section is usually the one that changes budgets.
Common questions
How is this different from monitoring?
Monitoring alerts when a rule matches. Hunting searches for the things no rule was written for, and then writes the rule. They answer different questions, and hunting is what surfaces the gap in your monitoring.
What data do you need access to?
Endpoint detection telemetry, identity and authentication logs, and network or proxy data cover most hypotheses. We work with what you have, and where something important is missing that becomes a finding rather than a blocker.
What happens if you find something live?
We stop hunting and tell you immediately, then move into containment with you. Finding active compromise mid-hunt is uncommon but not rare, and the handover into incident response happens the same day.
How often should hunting happen?
Quarterly suits most organisations, with an additional hunt after a significant change or a relevant published incident. Hunting once and never again gives you a snapshot and no detections worth keeping.
Does this replace penetration testing?
No. Testing asks whether an attacker could get in. Hunting asks whether one already has. Organisations that do both tend to discover that the answers are informative in different ways.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.