Home/IT Security/Threat hunting

03 · IT Security

Threat hunting

Proactive hunts for attackers already hiding in your network — hypothesis-driven work based on MITRE ATT&CK and threat intelligence, ending with confirmed findings and new detection rules for your SIEM.

MITRE ATT&CKhypotheses built on real attacker techniques
1–3 weekstypical hunt duration
quarterlyrecommended cycle

Service details

Assume they are already inside

No set of safeguards guarantees 100% protection. Threat hunting starts from the opposite assumption to most security tools: that an intruder may already be in your network, quiet and undetected. Our specialists actively search for that evidence instead of waiting for an alert.

Hunters build hypotheses from known attacker techniques, then look for their traces in your environment: unusual account activity, strange parent-child process relationships, suspicious outbound traffic, new scheduled tasks and changes in the file system. Experience matters — many seemingly meaningless traces together point to an intrusion that automated tools scored as normal.

  • Detection of attacks that existing tools missed
  • New detection rules for your SIEM after every hunt
  • A clear report for the board and for the technical team
IT Security

Method

How a hunt is run

Hypothesis-driven hunting

We take a specific attacker technique from MITRE ATT&CK or current threat intelligence — for example credential dumping or persistence through scheduled tasks — and look for its traces in your data.

Anomaly analysis

We establish what normal looks like in your environment and then investigate what does not fit: odd logon times, rare processes, unusual data volumes leaving the network.

Indicator sweeps

Fresh indicators of compromise from threat intelligence are swept across endpoints, logs and network traffic to confirm whether a known campaign has touched you.

Crown jewel focus

We start where an attacker would: domain controllers, identity systems, backup infrastructure, payment systems and the data that would hurt most if it leaked.

Traps and deception

Active hunting also means setting traps — decoy accounts, files and hosts that a legitimate user has no reason to touch, but an intruder does.

Detections that stay

Every confirmed technique becomes a new rule in the SIEM, so the same behaviour is caught automatically next time — your defences improve with each hunt.

Data sources

What we hunt in

The more telemetry we can reach, the deeper the hunt. We work with what you already have and tell you honestly where the blind spots are.

EDR / endpoint telemetryWindows and Linux logsActive Directory and Entra IDFirewall and proxyDNS queriesNetFlowVPN and remote accessMicrosoft 365Cloud audit logsWeb and application serversBackup systemsSIEM

Powered by our SIEM

Hunts run best on good data. We deliver SIEM as a service or a dedicated SIEM that scales to large volumes of logs, correlates events quickly and gives your team a dashboard of its own — with 24/7 log analysis by our specialists when you add our SOC.

Not sure which option to choose?

A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.

Book a consultation

How we work

A hunt in five steps

ScopingWe agree the scope, the crown jewels, the available telemetry and the rules of engagement.
Baseline and hypothesesWe learn what normal looks like and select the ATT&CK techniques most relevant to your sector.
The huntManual analysis supported by tooling across endpoints, logs and network data — typically one to three weeks.
Findings and responseConfirmed threats are escalated immediately with containment steps; we support forensics if needed.

What you get

  • Report for the management board and a technical report with evidence
  • List of confirmed threats and indicators of compromise
  • New detection rules and use cases for the SIEM
  • Hardening recommendations, prioritized by risk
  • Assessment of your telemetry — what you cannot see today

Questions and answers

Threat hunting FAQ

What is threat hunting?

It is the proactive search for attackers who are already inside the network but have not triggered any alert. Instead of waiting for a tool to shout, analysts form hypotheses about attacker behaviour and look for evidence of it in your telemetry.

How is it different from a penetration test?

A penetration test asks "could someone break in?". Threat hunting asks "did someone already get in, and are they still here?". The first looks for vulnerabilities, the second for traces of real activity.

How is it different from a SOC?

A SOC reacts to alerts around the clock. Threat hunting is a deliberate, time-boxed investigation without an alert to start from — it finds what the automated rules do not cover, and then turns those findings into new rules for the SOC.

How long does a hunt take?

Typically one to three weeks, depending on the size of the environment and the telemetry available. We recommend repeating hunts quarterly, and always after a major change or a security incident in your industry.

Do we need an EDR or SIEM first?

They help a lot, but are not mandatory. We can start with the logs you already have and tell you which blind spots to close first. If you have no SIEM, we can provide one as a service.

Will the hunt disrupt our systems?

No. Hunting is mostly read-only analysis of logs and telemetry. Anything more intrusive — for example collecting artefacts from a suspicious host — is agreed with you in advance.

What happens if you find an active intruder?

We escalate immediately, before the report is finished: you get the facts, the recommended containment steps and our help in executing them, together with forensic analysis of what happened.

Who performs the hunts?

Experienced security analysts from our team, using threat intelligence, MITRE ATT&CK techniques and their own investigative experience. Every engagement is covered by an NDA.

Does threat hunting help with NIS2 and DORA?

Yes. Both require organizations to detect threats and test the effectiveness of their security measures. Hunt reports and the resulting detection rules are concrete evidence — see NIS2 and DORA.

Related services

Often combined with this service

First step

Let's talk about Threat Hunting.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact