Threat Hunting
Threat Hunting: Searches for previously undetected attacker activity based on hypotheses. The term is part of operational security. People, processes, and technology must work together to evaluate alerts, coordinate measures, and implement insights effectively.
How it works and where it fits
Threat Hunting connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: Processed information regarding threat actors, tactics, indicators, and risks.
- Threat ModelingThreat ModelingAnalyzes potential attackers, attack vectors, and protective measures during the design phase.: Analyzes potential attackers, attack vectors, and protective measures during the design phase.
- Threat ActorThreat ActorAn individual, group, or organization that intentionally carries out or supports cyberattacks.: An individual, group, or organization that intentionally carries out or supports cyberattacks.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.