Threat Hunting

Threat hunting is the active search for attackers who are already lurking undetected in a computer network. Instead of waiting for an alert, professionals deliberately comb through network data for traces.

Most security programs in a company work like a burglar alarm. They know known attack patterns and go off when one of them appears. The problem: whoever proceeds cleverly triggers no alarm at all. Threat hunting reverses this principle. Professionals assume that someone is already sitting in the network and search specifically for evidence of that. So they don’t wait for a notification, but actively go looking themselves.

Why attackers remain undetected for months

Weeks or months often pass between a network breach and its discovery. Security firms speak of the dwell time. The longer this period lasts, the more damage occurs. Attackers use it to spread, collect passwords, and exfiltrate data.

Particularly dangerous are attacks that require no conspicuous malware. Anyone who has once obtained a valid password can simply log in normally. To the burglar alarm, this looks like an employee at work. This is exactly the gap in which threat hunting operates.

There is also an economic reason. A ransomware attack, in which all data is encrypted and released only for ransom, can paralyze a company for days. If the attacker is discovered during the preparation phase, the damage remains small. This is why banks, hospitals, and industrial corporations in particular afford themselves dedicated hunting teams.

From hypothesis to trace

A hunt begins with an assumption that can be verified. One example: an attacker might use stolen credentials to log in at night. The team then searches the log files for exactly this pattern. Such logs record who started which program and when.

The volumes of data are enormous, so software helps with filtering. A SIEM collects logs from the entire network in one place. EDR systems additionally observe what is happening on individual machines. Both systems provide the raw material, but the actual analysis is done by a human.

Increasingly, AI models take over the preliminary work. They learn what normal operations in a network look like and flag deviations. If an accounting computer suddenly sends large amounts of data abroad, that stands out. However, AI does not replace humans, since it also flags harmless outliers. The team decides which trace is worth pursuing.

If the hunt finds something, a new rule for automatic monitoring is created from it. This way, every discovered attack will be recognized immediately in the future. Even an unsuccessful hunt has value: it shows that a particular type of attack does not occur here.

Threat hunting in job postings and company announcements

The term appears regularly when a company reports a hacker attack. The statements then say that external specialists were brought in. These search the network for further backdoors left behind by the attacker. Without this step, the same perpetrator often returns after just a few weeks.

Because in-house teams are expensive, many companies purchase the service. Such offerings are called Managed Detection and Response. Providers like CrowdStrike, Microsoft, or Sophos sell them as a subscription. This is interesting for the stock market, because it means predictable recurring revenue.

A common misconception is confusing threat hunting with a penetration test. In a penetration test, hired specialists attack their own company to find vulnerabilities. In threat hunting, by contrast, one searches for a real attacker who is already present. One activity tests the wall, the other searches the house.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.