Kamran Mushtaq
Back to Cybersecurity
Cybersecurity

Threat Hunting

Added: July 6, 2026

Definition

  • Threat Hunting is proactively searching for hidden attackers even when no alert exists.
  • It works after SOC monitoring.

What Problem It Solves

Finds stealthy attacks that automated tools miss.

What Happens If Not Used

Skilled attackers may stay inside systems unnoticed.

Easy Wording

Instead of waiting for an alarm, you actively search for danger.

Layman Example

A detective looks for clues before anyone reports a crime.

Technical Example

Flow: Logs → SIEM → Hunter searches unusual PowerShell activity → Suspicious device found → Investigation.

Limitation: Threat Hunting finds suspicious activity but doesn't fully investigate what happened. That's the role of DFIR.