What Is Threat Hunting?

Also called: Cyber threat hunting

Related problems: Worried an attacker is already inside and our tools haven't noticed; Security tools only alert on what they already know about; Not sure whether our MDR provider actually hunts or just watches alerts; Need assurance after a breach at a peer or supplier

Threat hunting is the practice of proactively searching through an organization’s endpoints, networks, identity systems and logs for signs of attacker activity that automated security tools have not flagged. Rather than waiting for an alert, a hunter starts from an assumption, such as “an attacker might be using stolen credentials to move between servers,” and looks for evidence. It is usually performed by experienced analysts in an internal security team or as part of a managed security service.

At a glance

  • Threat hunting is proactive and human-led; it looks for what alerts missed.
  • Hunts usually start from a hypothesis based on threat intelligence, known attacker techniques or unusual patterns.
  • It depends on good data: endpoint, identity, network and cloud logs that are collected and retained.
  • Findings feed incident response and become new detection rules.
  • Many MDR and managed SOC services include some hunting; depth and frequency vary by provider.

What problem it solves

Security tools detect what they are built to recognize. Skilled attackers know this, so they use stolen credentials, legitimate administration tools and slow, quiet techniques designed to stay below alert thresholds. An attacker can sit in a network for weeks before doing visible damage, and the longer that goes on, the more data is taken and the harder recovery becomes.

Threat hunting shortens that window by actively looking for signs of compromise instead of assuming silence means safety. It also tests the detection setup itself: every hunt that finds something the tools missed reveals a gap that can be closed. For mid-sized companies, the challenge is that hunting needs skilled people with time to do it, which is why it is often bought as part of a service rather than built in-house.

How it works

Form a hypothesis. Hunters choose what to look for, often based on cyber threat intelligence (CTI) about active attacker groups, on frameworks that catalog attacker techniques such as MITRE ATT&CK, or on something unusual noticed in the environment.

Gather and search the data. They query telemetry from endpoint detection and response (EDR) tools, a security information and event management (SIEM) platform, identity providers, firewalls and cloud logs. Examples include logins at odd hours from new locations, administrative tools run on machines that never use them, or unusual outbound connections.

Investigate. Most leads turn out to be legitimate activity. Hunters dig into the ones that do not, building a timeline and deciding whether there is a real intrusion.

Respond and improve. Confirmed findings go to incident response. Whether or not anything is found, useful hunts are turned into new detection rules or automated searches, so the next occurrence raises an alert automatically.

Hunting is commonly performed by a security operations center (SOC), internal or outsourced, or by a managed detection and response (MDR) provider.

When it matters for buyers

  • When comparing MDR or managed SOC providers. “Threat hunting” appears in most proposals, but what it means in practice differs widely.
  • After a peer, supplier or industry is targeted. A focused hunt can check whether the same attacker has reached you.
  • When you have tools but no time. EDR and SIEM data is only valuable if someone looks at it.
  • When telemetry is thin. If key logs are not collected or kept long enough, hunting has little to work with, so data coverage comes first.

Our managed detection and response overview explains how hunting fits into a monitoring service.

Questions to ask vendors

  • How often do you hunt in our environment specifically, as opposed to across all customers?
  • Are hunts hypothesis-driven by analysts, automated queries, or both?
  • Which data sources do you hunt across, and how far back does the data go?
  • Will we receive a report of each hunt, including what was searched and what was found?
  • Can we request a hunt, for example after news of an attack on our industry, and is that included?
  • How do hunt findings turn into new detections for our environment?

How it differs from threat intelligence

Threat intelligence is information about attackers: who they are, which techniques and tools they use, and which indicators, such as addresses or file hashes, point to their activity. Threat hunting is the activity of searching your own environment for evidence of attacks. Intelligence often supplies the hypothesis for a hunt, and hunting can produce new intelligence, but one is knowledge and the other is investigation. Buying a threat intelligence feed does not mean anyone is looking for attackers in your network.

Frequently Asked Questions

Do we need threat hunting if we already have EDR and a SIEM?
Those tools detect activity that matches their rules and models. Threat hunting looks for what they missed, using their data. It is most valuable once the basics are in place and the data is being collected; without good telemetry there is little to hunt through.
Is threat hunting included in MDR services?
Often, but the depth varies a great deal. Some providers run regular hypothesis-driven hunts in each customer's data; others mainly run automated queries across all customers when a new threat appears and call that hunting. Ask how often hunts happen in your environment and what you will see from them.
How often should threat hunting be done?
There is no fixed rule. Many teams combine a regular cadence, such as monthly hunts on priority themes, with ad hoc hunts when new threat intelligence appears or after a relevant incident elsewhere. Continuous hunting is more typical of mature or outsourced security operations.
What happens when a hunt finds something?
The finding becomes an incident and moves into your incident response process: confirm it, contain it, investigate scope and remediate. Good hunting programs also turn findings into new detection rules so the same activity triggers an alert next time.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.