What Is Threat Hunting

Threat hunting is proactively searching for attackers who have evaded existing detections, instead of waiting for an alert. It is a senior blue team discipline that assumes a breach has already happened.

Threat hunting, defined

Most defensive work is reactive: an alert fires, an analyst responds. Threat hunting is the opposite. The hunter assumes an attacker is already inside and undetected, forms a hypothesis about how, and goes looking through the data to prove or disprove it.

Reactive response vs proactive hunting

Alert responseThreat hunting
TriggerAn alert firesA hypothesis
AssumptionDetection worksDetection missed something
OutputA closed ticketA new detection
SeniorityEntry to midSenior

The hypothesis driven process

  1. Form a hypothesis based on attacker behaviour
  2. Gather the relevant data
  3. Search for evidence of the technique
  4. Confirm or rule it out
  5. Turn a successful hunt into a permanent detection

Understanding attacker technique is essential, which is why hunters who know offensive security are the best. See red team vs blue team.

TakeawayA hunt that finds nothing is not wasted. Confirming an attacker is not using a technique is a valid, valuable result.

How to get there

Threat hunting is not an entry role. Build SOC and detection experience first, learn the attacker lifecycle, then move into hunting. The foundation is the SOC analyst syllabus.

Build toward threat hunting

SOC, detection engineering and hunting skills, live.

See the program

Frequently asked questions

What is threat hunting?

Proactively searching for attackers who evaded detection, instead of waiting for an alert to fire.

How is it different from alert response?

Response is triggered by an alert. Hunting is triggered by a hypothesis and assumes detection missed something.

Is threat hunting an entry level job?

No. It is senior. Build SOC and detection experience first, plus knowledge of attacker technique.

What skills does threat hunting need?

Log and data analysis, knowledge of the attacker lifecycle, and the ability to turn findings into detections.

What comes before threat hunting?

SOC analyst work and detection engineering, which build the foundation hunting requires.