Cybersecurity
Threat Hunting
Added: July 6, 2026
Definition
- Threat Hunting is proactively searching for hidden attackers even when no alert exists.
- It works after SOC monitoring.
What Problem It Solves
Finds stealthy attacks that automated tools miss.
What Happens If Not Used
Skilled attackers may stay inside systems unnoticed.
Easy Wording
Instead of waiting for an alarm, you actively search for danger.
Layman Example
A detective looks for clues before anyone reports a crime.
Technical Example
Flow: Logs → SIEM → Hunter searches unusual PowerShell activity → Suspicious device found → Investigation.
Limitation: Threat Hunting finds suspicious activity but doesn't fully investigate what happened. That's the role of DFIR.