Threat Hunting

Threat Hunting

Threat Hunting (proaktive Bedrohungssuche)

Threat hunting is the proactive, hypothesis-driven search for attackers who are already in the network but have not yet been caught by automatic alarms. Instead of waiting for an alarm, the hunter actively goes on the hunt for suspicious traces. It is the answer to the realisation that no detection system catches everything.

History & facts. Threat hunting starts where signature- and rule-based detection ends: with novel, disguised or particularly cautious attackers (see APT). The hunter forms hypotheses — such as „If an attacker uses this technique, it should show up in our data in such and such a way“ — and checks them systematically against logs, endpoint and network data. MITRE ATT&CK, which catalogues the tactics and techniques of real attackers, frequently serves as orientation. The prerequisite is good visibility: without sufficient, centrally available telemetry there is no hunt. Outlook & recommendation. Threat hunting is demanding and lives on experienced analysts, good data and solid threat intelligence that feeds hypotheses. It can be partly supported by automation and AI but does not replace human judgement. A recurring, documented process whose findings flow back into new detection rules is sensible. Within the scope of SOC and MDR services, hunting is part of NEOSEC's service profile — especially for customers who must assume they are a worthwhile target.
Threat Hunting — Threat Hunting