Skip to main content

Threat Hunting

Proactively test a bounded threat hypothesis in existing evidence when no alert has yet confirmed the activity.

Proactive hypothesis testing

Threat hunting is a planned search for evidence of harmful activity that existing alerts have not confirmed. It starts from a bounded hypothesis based on threat intelligence, architecture, incidents, anomalies, or known blind spots. Ad hoc searching without a question is analysis, not a repeatable hunt.

Hunt design

State behavior, adversary preconditions, assets, identities, time range, required sources, expected benign activity, query plan, stop condition, and escalation. Check source coverage and retention before work begins.

Use both specific observables and behavior. Trace alternate accounts, direct paths, renamed tools, low-volume activity, and changes an adversary needs to persist.

Outcomes

A hunt can find an incident, find benign behavior, expose missing evidence, validate a control, or produce a new detection. Record queries, source versions, time, assumptions, samples, findings, and disposition. Turn repeatable high-value logic into maintained detection with an owner.

Preserve evidence before containment when the finding can change volatile state.

Failure and residual risk

Confirmation bias can select only supporting data. Missing logs can appear as no activity. Broad searches create privacy and access risk. A clean result covers only the hypothesis, sources, retention, and period. Repeated manual hunts can waste analyst time when automation is possible.

Hunting does not replace monitoring or incident response. It improves them.

Pomerium boundary

Pomerium access evidence can support hunts for route bypass attempts, unusual identities, denied actions, policy changes, and session use on covered routes. It cannot prove absence from direct origins, endpoints, identity-provider administration, or application objects without those sources.

Evaluation checklist

  • What exact behavior, precondition, asset, identity, time, and observable defines the hunt?
  • Are source coverage, retention, schema, time, and known gaps verified before interpreting no result?
  • Did the analysis test alternate explanations and benign behavior?
  • Which finding becomes an incident, control fix, new source, maintained detection, or documented blind spot?
  • Is the hunt repeatable and proportionate in analyst time, data access, and privacy impact?

Sources and further reading

Keep learning

Security Operations and Risk

Cyber Threat Intelligence

Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.

Learn this term
Security Operations and Risk

Detection Quality

Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Attack Tree

An attack tree decomposes one attacker goal into alternate and combined paths that can achieve it.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo