Threat hunting is the practice of proactively searching through an organization’s endpoints, networks, identity systems and logs for signs of attacker activity that automated security tools have not flagged. Rather than waiting for an alert, a hunter starts from an assumption, such as “an attacker might be using stolen credentials to move between servers,” and looks for evidence. It is usually performed by experienced analysts in an internal security team or as part of a managed security service.
At a glance
- Threat hunting is proactive and human-led; it looks for what alerts missed.
- Hunts usually start from a hypothesis based on threat intelligence, known attacker techniques or unusual patterns.
- It depends on good data: endpoint, identity, network and cloud logs that are collected and retained.
- Findings feed incident response and become new detection rules.
- Many MDR and managed SOC services include some hunting; depth and frequency vary by provider.
What problem it solves
Security tools detect what they are built to recognize. Skilled attackers know this, so they use stolen credentials, legitimate administration tools and slow, quiet techniques designed to stay below alert thresholds. An attacker can sit in a network for weeks before doing visible damage, and the longer that goes on, the more data is taken and the harder recovery becomes.
Threat hunting shortens that window by actively looking for signs of compromise instead of assuming silence means safety. It also tests the detection setup itself: every hunt that finds something the tools missed reveals a gap that can be closed. For mid-sized companies, the challenge is that hunting needs skilled people with time to do it, which is why it is often bought as part of a service rather than built in-house.
How it works
Form a hypothesis. Hunters choose what to look for, often based on cyber threat intelligence (CTI) about active attacker groups, on frameworks that catalog attacker techniques such as MITRE ATT&CK, or on something unusual noticed in the environment.
Gather and search the data. They query telemetry from endpoint detection and response (EDR) tools, a security information and event management (SIEM) platform, identity providers, firewalls and cloud logs. Examples include logins at odd hours from new locations, administrative tools run on machines that never use them, or unusual outbound connections.
Investigate. Most leads turn out to be legitimate activity. Hunters dig into the ones that do not, building a timeline and deciding whether there is a real intrusion.
Respond and improve. Confirmed findings go to incident response. Whether or not anything is found, useful hunts are turned into new detection rules or automated searches, so the next occurrence raises an alert automatically.
Hunting is commonly performed by a security operations center (SOC), internal or outsourced, or by a managed detection and response (MDR) provider.
When it matters for buyers
- When comparing MDR or managed SOC providers. “Threat hunting” appears in most proposals, but what it means in practice differs widely.
- After a peer, supplier or industry is targeted. A focused hunt can check whether the same attacker has reached you.
- When you have tools but no time. EDR and SIEM data is only valuable if someone looks at it.
- When telemetry is thin. If key logs are not collected or kept long enough, hunting has little to work with, so data coverage comes first.
Our managed detection and response overview explains how hunting fits into a monitoring service.
Questions to ask vendors
- How often do you hunt in our environment specifically, as opposed to across all customers?
- Are hunts hypothesis-driven by analysts, automated queries, or both?
- Which data sources do you hunt across, and how far back does the data go?
- Will we receive a report of each hunt, including what was searched and what was found?
- Can we request a hunt, for example after news of an attack on our industry, and is that included?
- How do hunt findings turn into new detections for our environment?
How it differs from threat intelligence
Threat intelligence is information about attackers: who they are, which techniques and tools they use, and which indicators, such as addresses or file hashes, point to their activity. Threat hunting is the activity of searching your own environment for evidence of attacks. Intelligence often supplies the hypothesis for a hunt, and hunting can produce new intelligence, but one is knowledge and the other is investigation. Buying a threat intelligence feed does not mean anyone is looking for attackers in your network.
