SOC

Threat Hunting

Threat Hunting is the targeted search for attackers within a network who have not yet triggered a detection.

Threat Hunting is the targeted search for attackers who have not yet triggered an Alert. Analysts start with a hypothesis and actively test it against security data.

How it works

A hunt begins with an assumption, such as: 'An attacker is using legitimate remote access tools to move laterally within the network.' Analysts then search for corresponding traces in EDR, identity and network data. The outcome is a discovered attack, a new detection rule or a confirmed negative finding. Hunts are often triggered by new CTI reports or major vulnerabilities. They can also be triggered by gaps identified from previous incidents.

A practical example

A report describes a group infiltrating Swiss firms via a specific remote access tool. The SOC searches for installations of this tool across all customer environments. It finds the tool on two servers where its presence is not documented. One server shows connections to an unknown external address. A Case is then opened for investigation.

What to look out for

  • Hunts require high-quality data. Searching the past is impossible without sufficient log retention periods.
  • Every hypothesis should be documented, even if nothing was found.
  • Successful hunts should result in new detection rules.
  • Schedule hunts regularly. Otherwise, they get lost in daily operations.

Why it matters

Detection rules recognise what is already known. Skilled attackers use on-board tools and avoid known patterns. Threat Hunting closes this gap and shortens the time an attacker remains undetected.

Typical mistakes

Threat Hunting is often mistaken for just matching lists of IoCs. This is useful but does not replace searching for suspicious behaviour. Another mistake is conducting hunts without a clear outcome. These hunts fail to produce new rules or other valuable insights.

How we implement it

Threat Hunting is part of our SOC operations. The findings feed into our Detection Engineering process.

How ANOMAL implements this