01Practice
Threat hunting services: hypothesis-driven hunts across endpoint, identity and cloud telemetry
Structured hunts for attacker behavior that existing detections do not catch, run by analysts against your telemetry in Microsoft Sentinel, Defender XDR, Splunk, Elastic or the platform you own. Every hunt starts from a hypothesis mapped to MITRE ATT&CK and ends in a written result: a confirmed intrusion, a detection gap closed, or a technique shown to be absent, with the evidence for each.
- Name
- Threat Hunting
- Line
- 01 · Cybersecurity
- Type
- Practice, engaged on its own or within a program
01The problem
Alerts only find what someone already wrote a rule for.
Detection rules encode techniques that are known and expected. Attackers who use valid credentials, living-off-the-land binaries, OAuth consent or legitimate remote management tools often produce no alert at all, and their activity sits in logs that nobody queries.
Threat hunting is the discipline of asking the logs specific questions before an alert does: is this technique present in our environment, would we see it if it were, and what do we change so that next time it is caught automatically.
- Hunts end in detections
- A hunt that finds nothing still produces value when it closes with a tested detection rule or a logged telemetry gap. Each result is recorded so the hunt is not repeated by accident.
- Hypotheses, not browsing
- Every hunt states the technique, the data source it should appear in and what a positive result looks like before any query runs. Coverage is tracked against ATT&CK.
- Your platform, your queries
- Hunts run in the SIEM and EDR you already operate. The KQL, SPL or EQL used is handed over with the report so your analysts can rerun it.
02Scope
What threat hunting covers.
Hypothesis-driven hunts
Hunts built from ATT&CK techniques, threat intelligence relevant to your sector and the findings of recent penetration tests.
Identity and OAuth hunting
Token theft, consent grants, anomalous sign-in patterns, privilege changes and service principal abuse across Entra ID, Active Directory and cloud IAM.
Endpoint and lateral movement hunting
Living-off-the-land execution, persistence mechanisms, credential access and remote management tool abuse across EDR telemetry.
Cloud control plane hunting
IAM changes, unusual API activity, storage exposure and data-access patterns in AWS, Azure and Google Cloud audit logs.
Compromise assessment
A time-boxed hunt across the whole estate that answers whether an attacker is present now or has been recently, with evidence either way.
Detection gap analysis
Telemetry and detection coverage measured against the techniques hunted, with the gaps turned into onboarding and detection engineering work.
Hunt program design
A hunting cadence, a hypothesis backlog, templates and metrics for an internal team that wants to run hunts itself.
03Approach
How a threat hunting engagement runs.
MITRE ATT&CK for hypotheses and coverage, with queries written in KQL for Microsoft Sentinel and Defender XDR, SPL for Splunk and EQL or ES|QL for Elastic. Methods draw on [threat research](/security-labs/threat-research) and [detection engineering](/security-labs/detection-engineering) in Security Labs. See the guide to [threat hunting in Microsoft security environments](/resources/blog/threat-hunting-in-microsoft-security-environments).
Scope the telemetry
Confirm which sources exist, how far back they go and what is missing. A hunt is only as good as the logs it can see.
Build the hypothesis backlog
Select techniques by relevance to your sector, technology and recent findings. Each entry names the data source and the expected evidence.
Hunt
Run the queries, investigate what surfaces, and separate benign explanations from suspicious ones with context from asset and identity data.
Record and convert
Document each result. Confirmed activity moves to incident response. Suspicious patterns become tested detections. Missing telemetry becomes an onboarding task.
Report and repeat
A report for leadership and a technical annex with every query. The backlog is refreshed and the next hunt begins from the gaps found.
04Deliverables
Threat hunting deliverables.
- A hypothesis backlog mapped to MITRE ATT&CK, with the data source for each
- A hunt report per cycle: findings, benign explanations and evidence
- Detection rules written and tested from suspicious patterns found
- A telemetry gap list with onboarding priorities
- Every query used, in the language of your platform, for your analysts to rerun
When this work fits
- Security teams with a SIEM or EDR in place that want to look beyond the alerts it raises
- Organizations that suspect undetected activity after a phishing campaign, a vendor breach or a merger
- Managed SOC customers who want a periodic hunting cycle added to monitoring
- Internal teams building their own hunting program and wanting a method to start from
05Questions
Threat hunting: questions we are asked
Monitoring waits for an alert and investigates it. Hunting starts from a hypothesis about a technique and goes looking for it in the data, whether or not an alert exists. The two reinforce each other: hunts produce new detections, and monitoring tells hunters where the noise is.
That is a result, and it is written down. Either the technique is absent from the period searched, which is recorded with the queries used so the hunt can be repeated, or the telemetry to see it does not exist, which becomes an onboarding task. Many hunts end with a new detection rule even when nothing malicious was found.
Read access to the SIEM, EDR and cloud audit logs is enough for most hunts. Access is scoped, logged and time-limited, and nothing is changed in your environment. Where a hunt confirms an intrusion, containment is agreed with you and handled by the incident response team.
Yes. Hunting runs as a periodic cycle alongside 24×7 monitoring in our managed SOC, with coverage hours and the hunting cadence set in the service agreement. It can also be delivered as a standalone compromise assessment or a quarterly engagement for teams that run their own SOC.
Often alongside
Related services, industries and guides
Working with us
What every engagement rests on.
- Non-disclosure agreements
- Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
- Least-privilege access
- The minimum access the work requires, tied to named individuals and removed when the work ends.
- Telemetry stays in your tenant
- In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
- End of engagement
- Access is handed back, and your information is returned or deleted as agreed with you.
Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India
