Threat Hunting

Articles about threat hunting from security operations practitioners.

Threat Hunting

Threat hunting solutions: where the story ends

A threat hunting solution is really three different products with three different handoff points. Here's the procurement test that finds where each vendor's story ends and yours begins.

DCDaniel C. · Sep 25, 2026
Threat Hunting

A hunt we ran that found nothing, and why it mattered

I closed the ticket in about nine minutes. Weeks later an intel report made me reopen it as a by-hand hunt against old logs. The hunt found nothing, and that empty result was worth more than most of the true positives I have escalated.

MKMarta K. · Aug 22, 2026
Threat Hunting

Most threat hunting programs produce activity theater

The threat hunting program I inherited looked healthy on a slide: a hunt calendar, ATT&CK coverage in the high seventies, tidy quarterly reports. Not one hunt had changed a detection in eighteen months. This is how I separate a real hunt from a rebranded IOC sweep.

MKMarta K. · Aug 7, 2026
Threat Hunting

IOC sweeps vs. TTP hunting: the difference changes what you fund

Our MDR renewal packet had a line item for proactive threat hunting, so I asked the account team to show me the hypothesis behind their last hunt. What came back was an indicator sweep with a hunting price tag. Paying hunting rates for work a script runs is a line item worth auditing before the next renewal.

DCDaniel C. · Aug 3, 2026
Threat Hunting

What threat hunters actually do on a Tuesday

Threat hunters spend Tuesday testing one written hypothesis against messy data, not browsing logs for fun. The real output is a shipped detection or a documented gap, even when the hunt finds nothing.

MKMarta K. · Jul 11, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Threat Hunting | Future of SecOps