Proactive hypothesis testing
Threat hunting is a planned search for evidence of harmful activity that existing alerts have not confirmed. It starts from a bounded hypothesis based on threat intelligence, architecture, incidents, anomalies, or known blind spots. Ad hoc searching without a question is analysis, not a repeatable hunt.
Hunt design
State behavior, adversary preconditions, assets, identities, time range, required sources, expected benign activity, query plan, stop condition, and escalation. Check source coverage and retention before work begins.
Use both specific observables and behavior. Trace alternate accounts, direct paths, renamed tools, low-volume activity, and changes an adversary needs to persist.
Outcomes
A hunt can find an incident, find benign behavior, expose missing evidence, validate a control, or produce a new detection. Record queries, source versions, time, assumptions, samples, findings, and disposition. Turn repeatable high-value logic into maintained detection with an owner.
Preserve evidence before containment when the finding can change volatile state.
Failure and residual risk
Confirmation bias can select only supporting data. Missing logs can appear as no activity. Broad searches create privacy and access risk. A clean result covers only the hypothesis, sources, retention, and period. Repeated manual hunts can waste analyst time when automation is possible.
Hunting does not replace monitoring or incident response. It improves them.
Pomerium boundary
Pomerium access evidence can support hunts for route bypass attempts, unusual identities, denied actions, policy changes, and session use on covered routes. It cannot prove absence from direct origins, endpoints, identity-provider administration, or application objects without those sources.
Evaluation checklist
- What exact behavior, precondition, asset, identity, time, and observable defines the hunt?
- Are source coverage, retention, schema, time, and known gaps verified before interpreting no result?
- Did the analysis test alternate explanations and benign behavior?
- Which finding becomes an incident, control fix, new source, maintained detection, or documented blind spot?
- Is the hunt repeatable and proportionate in analyst time, data access, and privacy impact?
