Threat Hunting

Threat Hunting is the proactive search for new, unknown threats that existing security mechanisms have not yet detected. Unlike pure alert handling, threat hunting often starts with hypotheses, anomalies or known attack patterns. Analysts then examine telemetry, processes and behavioral data to find hidden activities or early indicators. This approach is particularly valuable against skilled, persistent attackers who work with legitimate tools or inconspicuous techniques.

Threat hunting thereby increases the chance of discovering advanced attacks earlier. At the same time, the findings often result in new rules, playbooks and improvements to existing security controls. For organizations, threat hunting is therefore a maturity indicator of modern security operations. The term stands for active defense instead of mere reaction to already confirmed alerts. Where internal resources are lacking, Managed Services can complement these capabilities operationally. Operationally, automated attack detection helps to separate relevant signals from less critical events more quickly.

See also: Security Operations Center, Threat Intelligence and Adversary Intelligence.