01Introduction
Detection rules catch what someone thought to write a rule for. Skilled attackers aim for the gaps. Threat hunting assumes they're already inside and goes looking.
02What is Threat hunting?
Threat hunting is the proactive, human-led search through telemetry for signs of compromise that automated detections did not flag. Hunts usually start from a hypothesis grounded in threat intelligence or a MITRE ATT&CK technique.
It relies on rich data from EDR, XDR and the SIEM. Successful hunts end in two outputs: an incident response case if something is found, and a new detection so the next occurrence is caught automatically.
03How Threat hunting works
A hunt is a small investigation with a clear question.
- 1.
Form a hypothesis
For example: an attacker is using a stolen service account token to access production data.
- 2.
Collect and query
Pull the relevant logs and search for the behavior, not a known indicator.
- 3.
Investigate anomalies
Separate suspicious activity from normal but unusual operations.
- 4.
Operationalize
Escalate real findings, then turn the query into a standing detection and document the hunt.
04Threats and risks
Hunting targets threats built to avoid alerts.
Living off the land
Attackers using legitimate admin tools that signature-based detection ignores.
Credential abuse
Valid accounts used from unusual places or at unusual times.
Long dwell time
Quiet persistence that goes unnoticed for months.
Data gaps
Hunts are limited by missing or short-retention logs.
05How Parameter helps
Parameter gives hunters concrete hypotheses: attack paths proven to work in your environment.
Proven attack paths
The pentesting agents show exactly how an attacker would move, which becomes a hunt hypothesis.
Cloud identity paths
Cloud Security maps identity and attack paths worth watching.
Close what you find
Retests confirm the weakness behind a hunt finding is actually fixed.

