03 · IT Security
Proactive hunts for attackers already hiding in your network — hypothesis-driven work based on MITRE ATT&CK and threat intelligence, ending with confirmed findings and new detection rules for your SIEM.
Service details
No set of safeguards guarantees 100% protection. Threat hunting starts from the opposite assumption to most security tools: that an intruder may already be in your network, quiet and undetected. Our specialists actively search for that evidence instead of waiting for an alert.
Hunters build hypotheses from known attacker techniques, then look for their traces in your environment: unusual account activity, strange parent-child process relationships, suspicious outbound traffic, new scheduled tasks and changes in the file system. Experience matters — many seemingly meaningless traces together point to an intrusion that automated tools scored as normal.
Method
We take a specific attacker technique from MITRE ATT&CK or current threat intelligence — for example credential dumping or persistence through scheduled tasks — and look for its traces in your data.
We establish what normal looks like in your environment and then investigate what does not fit: odd logon times, rare processes, unusual data volumes leaving the network.
Fresh indicators of compromise from threat intelligence are swept across endpoints, logs and network traffic to confirm whether a known campaign has touched you.
We start where an attacker would: domain controllers, identity systems, backup infrastructure, payment systems and the data that would hurt most if it leaked.
Active hunting also means setting traps — decoy accounts, files and hosts that a legitimate user has no reason to touch, but an intruder does.
Every confirmed technique becomes a new rule in the SIEM, so the same behaviour is caught automatically next time — your defences improve with each hunt.
Data sources
The more telemetry we can reach, the deeper the hunt. We work with what you already have and tell you honestly where the blind spots are.
Hunts run best on good data. We deliver SIEM as a service or a dedicated SIEM that scales to large volumes of logs, correlates events quickly and gives your team a dashboard of its own — with 24/7 log analysis by our specialists when you add our SOC.
A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.
How we work
Questions and answers
It is the proactive search for attackers who are already inside the network but have not triggered any alert. Instead of waiting for a tool to shout, analysts form hypotheses about attacker behaviour and look for evidence of it in your telemetry.
A penetration test asks "could someone break in?". Threat hunting asks "did someone already get in, and are they still here?". The first looks for vulnerabilities, the second for traces of real activity.
A SOC reacts to alerts around the clock. Threat hunting is a deliberate, time-boxed investigation without an alert to start from — it finds what the automated rules do not cover, and then turns those findings into new rules for the SOC.
Typically one to three weeks, depending on the size of the environment and the telemetry available. We recommend repeating hunts quarterly, and always after a major change or a security incident in your industry.
They help a lot, but are not mandatory. We can start with the logs you already have and tell you which blind spots to close first. If you have no SIEM, we can provide one as a service.
No. Hunting is mostly read-only analysis of logs and telemetry. Anything more intrusive — for example collecting artefacts from a suspicious host — is agreed with you in advance.
We escalate immediately, before the report is finished: you get the facts, the recommended containment steps and our help in executing them, together with forensic analysis of what happened.
Experienced security analysts from our team, using threat intelligence, MITRE ATT&CK techniques and their own investigative experience. Every engagement is covered by an NDA.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact