What Is Threat Hunting? Process, Types, Techniques & Examples

Threat hunting is the proactive search for attackers who evaded automated detection. Learn the process, types, techniques, a real hunt example, and metrics.
Published on
Wednesday, September 23, 2026
Updated on
September 23, 2026

Threat hunting is the proactive, analyst-led search for attacker activity that has evaded automated security controls across endpoints, networks, identity systems, and cloud environments.

Detection tools wait for activity to match a rule. Hunters start from the assumption that an intruder is already inside, form a testable hypothesis about how that intruder operates, and search existing telemetry for the evidence.

A successful hunt produces more than a single finding for the incident queue. Each confirmed technique becomes a new detection, so the next attacker using it triggers an alert instead of requiring another hunt.

Why Threat Hunting Assumes a Breach Already Happened

Threat hunting rests on one premise: some attackers are already inside, and no alert has fired. Automated detection misses them for predictable reasons.

  • Valid credentials: Attackers signing in with stolen passwords or session tokens generate authentication events that look like normal work.
  • Living off the land: PowerShell, WMI, remote management tools, and scheduled tasks do the attacker's work without introducing files antivirus recognizes.
  • New or custom tooling: Implants written for one campaign have no signature until someone analyzes them.
  • Telemetry gaps: Firewalls, VPN gateways, and SaaS platforms produce limited logs, so activity there never reaches detection rules.
  • Low-and-slow pacing: Small actions spread over weeks never cross volume-based thresholds.

Hunting targets those blind spots on purpose, one hypothesis at a time. It asks what an attacker does next in this specific environment, then checks whether it already happened.

Why Threat Hunting Matters

Attackers still stay hidden long enough to reach their objectives inside most environments. Mandiant's M-Trends 2026 reported a global median dwell time of 14 days.

The SANS 2025 Threat Hunting Survey shows why behavior-focused hunting pays off: 76% of organizations reported living-off-the-land techniques in nation-state attacks, and business email compromise remained the threat most discovered through hunting.

Here is why threat hunting is important:

  • Shorter dwell time: Hunters find intrusions that otherwise run until an external party reports them.
  • New detections: Every confirmed technique becomes an automated rule, which compounds coverage over time.
  • Visibility gaps exposed: Hunts reveal missing logs and unmonitored systems before an incident does.
  • Faster incident response: Responders start with the attacker's techniques already mapped.
  • Better advanced threat coverage: Behavior-based hunting finds advanced persistent threats that avoid signature-based tools.

Threat Hunting vs Threat Detection

Threat detection flags known malicious activity automatically as it happens, while threat hunting searches for activity that no rule has flagged yet.

Aspect Threat Hunting Threat Detection
Starting point Analyst hypothesis or intelligence Rule, signature, or model match
Driver Human-led, supported by tooling Automated, reviewed by analysts
Target Unknown or evasive activity Known patterns and behaviors
Cadence Time-boxed hunts on a schedule or trigger Continuous, in real time
Output Findings, new detections, and data gap reports Alerts for triage and response

Each discipline strengthens the other. Hunts create the detection rules that automated tooling runs, and detection gaps point hunters to the techniques worth testing next.

How the Threat Hunting Process Works

Threat hunting follows a repeatable six-stage cycle that begins with a hypothesis and ends by turning what the team learns into stronger detection and monitoring.

threat hunting process cycle

1. Form a Hypothesis

Create a testable hypothesis using threat intelligence, previous incidents, emerging attacker behavior, or known TTPs. Example: “A threat actor targeting our sector may be using scheduled tasks to maintain persistence on Windows file servers.”

2. Scope the Data

Identify the systems, users, logs, and time periods needed to test the hypothesis. This may include endpoint telemetry, authentication logs, DNS activity, network flows, cloud logs, or SIEM data. Confirm that the required telemetry is available and detailed enough to support the hunt.

3. Investigate the Telemetry

Search the selected data for behavior that supports or challenges the hypothesis. Hunters pivot from suspicious events into related processes, accounts, endpoints, domains, IP addresses, authentication chains, and network connections to understand the full activity path.

4. Validate the Findings

Determine whether suspicious activity is genuinely malicious or the result of legitimate administrative or business activity. Validate findings using asset ownership, user context, approved changes, threat intelligence, and historical behavior.

5. Escalate or Close the Hunt

Confirmed malicious activity is escalated to incident response for containment, investigation, and remediation. If the hypothesis is not supported, document the evidence reviewed and close the hunt so the same work does not need to be repeated unnecessarily.

6. Operationalize the Findings

Turn useful findings into lasting security improvements. This can include creating or refining detection rules, updating threat-hunting playbooks, enriching indicators, documenting new attacker behaviors, and identifying telemetry gaps that security engineering teams need to address.

The process then feeds back into future hunts, allowing each investigation to improve the organization’s detection coverage and hunting maturity.

Hypothesis quality decides the outcome more than tooling does. Structured threat analysis of which actors target the organization produces sharper hypotheses than generic checklists do.

Types of Threat Hunting

Threat hunting is commonly divided into three types based on what initiates the investigation: a known attacker behavior, a detected signal, or an organization-specific risk.

threat hunting types

1. Structured Threat Hunting

Structured threat hunting begins with a defined hypothesis based on known attacker tactics, techniques, and procedures (TTPs), often mapped to the MITRE ATT&CK framework. Hunters then search telemetry for behavioral patterns associated with those techniques, even when no known indicator of compromise is present.

Example: A team hunts for signs of credential dumping by searching endpoint and authentication logs for behaviors associated with MITRE ATT&CK technique T1003, even though no alert has been triggered.

2. Unstructured Threat Hunting

Unstructured threat hunting begins with a trigger such as an indicator of compromise (IoC), suspicious event, or detected anomaly. Analysts investigate activity surrounding that signal to determine its origin, identify related systems or accounts, and uncover additional signs of compromise.

Example: A SOC discovers a device communicating with a known malicious IP address. Hunters trace related network connections, processes, user activity, and endpoints to determine whether the communication is part of a broader compromise.

3. Situational Threat Hunting

Situational threat hunting is driven by risks specific to the organization. A hunt may focus on a critical asset, newly exposed service, emerging vulnerability, or threat campaign targeting the organization’s industry. This directs hunting resources toward environments and attack scenarios with the greatest potential impact.

Example: After learning that attackers are targeting financial institutions through exposed VPN appliances, a bank hunts specifically for unusual authentication activity, configuration changes, and suspicious sessions involving its internet-facing VPN infrastructure.

Current intelligence drives all three types of hunting. A new campaign report can seed a structured hunt, supply the indicators for an unstructured one, or shift situational focus to the systems that the campaign targets.

Threat Hunting Techniques

threat hunting detection techniques
  • Indicator sweeps: Search logs and endpoints for known malicious hashes, IP addresses, and domains, a fast check with a short shelf life.
  • Behavior hunting: Look for technique patterns, such as office applications spawning scripting engines or service accounts logging in interactively.
  • Stacking: Count occurrences of an attribute across the fleet, such as autorun entries or scheduled task names, and investigate the rarest values.
  • Baselining and anomaly analysis: Establish normal activity for a user, host, or service, then examine deviations in time, volume, or destination.
  • Clustering and grouping: Group related events, such as logons from the same source, to expose coordinated activity no single event reveals.
  • Intelligence-led pivoting: Take an actor's reported infrastructure or tooling and pivot outward to related domains, certificates, and hosts in internal logs.

Why Threat Hunters Target Behavior: The Pyramid of Pain

The Pyramid of Pain, published by David Bianco in 2013, ranks indicator types by how much pain denying them causes an attacker.

  • Hash values: Trivial for attackers to change, since recompiling a file produces a new hash.
  • IP addresses: Easy to rotate through new hosting or proxies.
  • Domain names: Simple to replace, at the cost of a registration.
  • Network and host artifacts: Annoying to change, since they require modifying tools and habits.
  • Tools: Challenging to replace, since new tooling takes time to build or buy.
  • Tactics, techniques, and procedures: Tough to change, since they reflect how the operator works.

Hunting at the top of the pyramid forces attackers to change how they operate, not just where they host. That is why mature programs hunt for behaviors such as credential dumping with tools like Mimikatz instead of chasing a single hash.

A Threat Hunt Example: APT36 on Linux Endpoints

CloudSEK researchers documented an APT36 campaign against Indian government and defense entities that delivered malware through Linux desktop entry files. The findings translate directly into a hunt.

Hypothesis: An espionage actor targeting the sector is using .desktop files disguised as PDF documents to run hidden shell commands on Linux workstations.

  • File creation: Files with double extensions such as .pdf.desktop appearing in download folders or extracted ZIP archives.
  • Process lineage: A desktop launcher spawning a shell that fetches content from Google Drive, writes a file to /tmp, marks it executable, and runs it.
  • Decoy behavior: A browser opening a PDF at the same moment an unknown binary starts in the background.
  • Persistence: New autostart entries, cron jobs, or systemd units created shortly after the launcher ran.
  • Command and control: Outbound WebSocket connections from binaries located in temporary directories.

A clean result documents that the technique is absent and the data exists to see it. A positive result goes to incident response, and either outcome ends with a detection rule for .desktop files that launch network retrieval from temporary paths.

Threat Hunting Use Cases

  • Account compromise: Impossible travel, new MFA registrations, and logons from infrastructure tied to leaked credentials.
  • Lateral movement: Unusual RDP, SMB, WinRM, and remote service activity between hosts that rarely communicate.
  • Ransomware staging: Shadow copy deletion, bulk archiving, and security tool tampering in the days before encryption.
  • Command and control: Regular beaconing intervals, DNS queries to newly registered domains, and traffic patterns typical of botnet implants.
  • Data exfiltration: Large transfers to cloud storage, archives in temporary folders, and uploads at unusual hours.
  • SaaS and OAuth abuse: New third-party app grants with broad permissions and bulk exports from CRM or file-sharing tenants.
  • Edge device persistence: Unexpected configuration changes, new accounts, and modified files on VPN gateways and firewalls.

Threat Hunting Tools and Data Sources

EDR and XDR platforms ranked as the top threat hunting tools in the SANS 2025 survey, followed by SIEM and network detection and response.

  • EDR and XDR: Process, file, registry, and memory telemetry from endpoints and servers.
  • SIEM and security data lakes: Centralized, searchable logs across endpoints, identity, network, and cloud.
  • Network detection and response: Flow records, DNS logs, and protocol metadata that reveal beaconing and lateral movement.
  • Identity and cloud audit logs: Sign-in events, role changes, and API activity from identity providers and cloud platforms.
  • Threat intelligence platforms: Actor profiles, campaign reporting, and indicators that seed hypotheses.
  • Query languages and notebooks: KQL, SPL, and Sigma rules for repeatable searches, and notebooks for documenting analysis.

Data depth matters more than the number of tools in the stack. A hunt fails when the logs needed to test the hypothesis were never collected, which makes data gap tracking a standing output of every program, alongside broader security monitoring.

Threat Hunting Maturity and Metrics

The Hunting Maturity Model, created by David Bianco, describes five levels of hunting capability.

  • HMM0, Initial: Relies entirely on automated alerting, with little routine data collection.
  • HMM1, Minimal: Searches for threat intelligence indicators across collected data.
  • HMM2, Procedural: Follows hunting procedures created by others, with high data collection.
  • HMM3, Innovative: Creates new hunting procedures and applies analysis techniques such as stacking.
  • HMM4, Leading: Automates successful hunts into detections, freeing hunters for new hypotheses.

Useful hunting metrics track outcomes instead of activity volume. Detections created from hunts, ATT&CK techniques covered, data gaps closed, and intrusions found before external notification show whether hunting improves defense.

Staffing sets the pace of progress. The SANS 2025 survey found 61% of organizations cite skilled staff shortages as a primary barrier, while 45% now update hunting methodologies as needed, up from 35% in 2024.

Threat Hunting Best Practices

  1. Seed hypotheses with current intelligence on actors targeting the organization's sector and technology.
  2. Time-box each hunt, with a defined data scope and an end date, so hunts finish with an answer.
  3. Document every hunt as a package, including hypothesis, queries, data sources, and results, so others can repeat it.
  4. Convert findings into detections within a defined service level, so each hunt raises baseline coverage.
  5. Rotate across ATT&CK tactics to avoid hunting only the techniques the team already knows.
  6. Track data gaps as findings, and route them to engineering with the same priority as threats.
  7. Coordinate with incident response and CTI, so escalations move quickly and hunt results feed intelligence.
  8. Measure outcomes quarterly and report them to the SOC and security leadership.

Intelligence-Led Threat Hunting With CloudSEK Threat Intelligence

Hunting quality rises and falls with its hypotheses, and the best hypotheses come from knowing which adversaries target the organization and how they operate today.

CloudSEK Threat Intelligence tracks threat actors and their TTPs, exploited CVEs, malware, and ransomware campaigns, curated to a customer's industry and region. The APT36 hunt above started from exactly that kind of research, turning a published campaign into specific searches a team runs in its own SIEM and EDR.

CloudSEK's guide to how threat intelligence improves incident response and threat hunting covers the workflow from intelligence to investigation in more detail.

Threat Hunting FAQs

Who performs threat hunting?

Dedicated threat hunters, senior SOC analysts, detection engineers, and incident responders perform it, with managed hunting providers supporting some programs.

How often should threat hunting be performed?

Continuously in mature programs, with time-boxed hunts launched on a schedule and whenever new intelligence or a major vulnerability disclosure arrives.

What is the difference between threat hunting and incident response?

Threat hunting searches for undiscovered intrusions. Incident response contains, investigates, and recovers from an intrusion once it is confirmed.

Can small organizations do threat hunting?

Yes. Small teams hunt a few high-value hypotheses on critical systems, or use a managed detection provider that includes hunting.

What skills do threat hunters need?

Log and query fluency, operating system internals, network analysis, knowledge of ATT&CK techniques, and the ability to reason from incomplete evidence.

Can threat hunting be automated?

Partially. Automation handles data collection and repeated searches, while hypothesis creation and judging ambiguous activity still require human analysts.

Related Posts
Malware vs. Virus vs. Worm: How They Spread & Key Differences
Malware is malicious software; viruses replicate inside a host file, and worms spread as standalone programs. Their replication methods determine how infections continue.
12 SaaS Security Threats and How to Mitigate Them
SaaS security threats include stolen credentials, session hijacking, and data loss. Mitigation requires secure sign-ins, limited permissions, and controlled integrations.
Capital One Data Breach (2019): Attack Path, Root Causes, and Cloud Security Lessons
The Capital One breach shows how a misconfigured WAF, AWS credentials, IAM permissions, and S3 access formed an attack path, plus where cloud defenses can stop it today.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.