Threat Hunting
Threat hunting is the proactive, human-led search for threats that automated security tools have not detected. Hunters form hypotheses about attacker behavior, then query security telemetry (logs, EDR data, network flows) to confirm or refute them using TTPs from frameworks like MITRE ATT&CK.
Frequently Asked Questions
What is Threat Hunting?
Threat hunting is the proactive, human-led search for threats that automated security tools have not detected. Hunters form hypotheses about attacker behavior, then query security telemetry (logs, EDR data, network flows) to confirm or refute them using TTPs from frameworks like MITRE ATT&CK.
How is Threat Hunting related to TTP (Tactics, Techniques, and Procedures)?
Threat Hunting and TTP (Tactics, Techniques, and Procedures) are both key concepts in threat intelligence. TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
Related Terms
TTP (Tactics, Techniques, and Procedures)
TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
MITRE ATT&CK
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. It is used as a foundation for threat detection, red team exercises, and gap analysis in security programs. The framework covers Enterprise, Mobile, and ICS environments.
IOC (Indicator of Compromise)
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.