Threat hunting Wikipedia

threat hunting

They focus on behaviors such as repeated RDP connections, abnormal Kerberos ticket use, pass-the-hash attempts, and unusual SMB or WMI activity. Successful validation either confirms malicious activity or strengthens confidence in current controls. Analysts iterate based on initial results, refining detection logic or pivoting to adjacent behaviors. Hunters start with a hypothesis — for example, that adversaries are abusing service accounts for lateral movement — and design queries against relevant telemetry. Threat intelligence drives proactive threat hunting by anchoring hypotheses in real-world adversary behavior.

  • Threat hunters uncover these gaps by identifying post-compromise activity without corresponding alerts.
  • This technique involves searching massive security datasets to identify security threats.
  • At its core, threat hunting aims to understand attacker methodologies, improve detection capabilities, and strengthen your organization’s overall security posture through continuous learning and adaptation.
  • It demands a particularly qualified specialist with much patience, critical thinking, creativity, and an excellent eye for finding prey, usually in the form of network behavior anomalies.
  • Scheduled threat hunting, where time is dedicated for staff to conduct hunts at regular intervals, is an improvement and can allow organizations to prioritize searches at different times and improve efficiency.

Furthermore, FortiResponder provides managed threat hunting for organizations without a SOC team, ensuring faster detection and response. A well-crafted threat hunting program supplements incident response in various ways, primarily by identifying potential threat variables that can put an organization in harm’s way. Adding the expertise of human analysts can provide that extra layer of security for your organization. Ideally, organizations with sufficient staff and budget should engage in continuous, real-time threat hunting in which the network and endpoints are proactively engaged to uncover attacks on the network as part of a sustained effort. Threat hunters need a solid understanding of the organization’s profile, business activities that could attract threat actors (such as hiring new staff or acquiring new assets, companies, etc), https://gleecus.com/blogs/cybersecurity-in-digital-transformation/ and baseline usage.

threat hunting

Intelligence enriches raw telemetry by linking observed behaviors to known threats, enabling prioritization based on relevance and risk. Establish structured campaigns, rotate focus areas, and tie hunts to operational priorities. Effective hunters begin with a clear hypothesis grounded in threat intelligence, recent TTPs, or infrastructure-specific risk.

Dwell time

You should also measure how hunting activities contribute to threat intelligence development, including new indicators of compromise documented and attack patterns identified that weren’t previously known to your organization. Beyond counting incidents and alerts, meaningful threat hunting metrics focus on the quality and relevance of discoveries. These metrics help you understand whether your hunting efforts are uncovering genuine threats and contributing to stronger security defenses over time. This integration transforms threat hunting from an isolated activity into a force multiplier that enhances every aspect of your security operations. When integrated with SOAR platforms, threat hunting findings can trigger automated response workflows, accelerating containment and remediation while ensuring consistent handling of similar threats in the future.

Retaining security data for extended periods of time enables threat hunters to extract enhanced visibility and threat context from real-time and historical data, supporting the completeness and accuracy of investigation and analysis. The service must also have the ability to gather and store granular system events data in order to provide absolute visibility into all endpoints and network assets. Since proactive hunting depends on human interaction and intervention, success depends on who is hunting through the data. Human threat hunters are an absolutely critical component in an effective threat hunting service. Every new generation of security technology is able to detect a greater number of advanced threats — but the most effective detection engine is still the human brain. Unfortunately, there is a major skills shortage in the cybersecurity industry when it comes to threat hunting, meaning that seasoned hunters don’t come cheap.

threat hunting

Organizations that implement threat hunting programs report substantial improvements in their security posture. Even more critically, certain stealthy espionage campaigns are now averaging 393 days of dwell time—far outlasting standard log retention policies. According to Mandiant’s https://adeptiv.ai/ai-compliance-platform-guide/ M-Trends 2026 report, the global median dwell time for attackers in 2025 rose to 14 days, driven largely by actors establishing persistence in edge devices that lack standard telemetry.

Threat Hunting FAQs

threat hunting

This guide explores the principles of threat hunting, its benefits, and the techniques used by security professionals. Building an effective threat hunting team requires assembling professionals with diverse technical skills and analytical capabilities who can work together to uncover sophisticated threats. These measurements help justify continued investment in threat hunting capabilities and guide program optimization by highlighting which hunting methodologies and focus areas deliver the greatest return. Monitor the reduction in attacker dwell time, the percentage of incidents detected through hunting versus automated alerts, and the number of security control improvements implemented based on hunting findings.

  • To be even more effective and efficient, however, threat hunting can be partially automated, or machine-assisted, as well.
  • However, scheduled threat hunting has the drawback of offering a certain dwell time for advanced attacks to try to operate in between those intervals, so the shorter the interval, the better.
  • High-quality baselines and contextual enrichment reduce false positives and increase precision in surfacing stealthy attacker behaviors.
  • Hunting also reveals where logs are incomplete, visibility gaps exist, or critical data sources are misconfigured.

A situational hunt is a response to an organization’s unique situation. It is often triggered by the discovery of an indicator of compromise (IoC) in an organization’s system. Formal frameworks, such as the MITRE Adversary Tactics Techniques and Common Knowledge (ATT&CK) framework, guide structured hunts.