Proactive searching through systems and data to find threats that automated tools have missed.
Threat hunting is the proactive, human-led search for threats that have evaded automated detection. Rather than waiting for alerts, threat hunters form hypotheses about how attackers might operate in their environment and actively search for evidence. They analyse logs, endpoint telemetry, and network traffic looking for subtle indicators of compromise—unusual user behaviour, suspicious process chains, or communication with known bad infrastructure. Threat hunting assumes that sophisticated attackers may already be present and focuses on finding them before they achieve their objectives.
Why It Matters
The DSC Perspective:
Automated tools miss sophisticated attacks. Threat hunting finds attackers who have slipped past your defences and are quietly operating in your environment. MDR services often include threat hunting as part of their offering.
