Managed Security Operations

Threat Hunting

Search proactively for attacker behaviour that preventive controls may have missed.

Engagement focus

Hypothesis-led hunts using endpoint, identity, network and cloud evidence with documented findings and limitations.

Hypothesis-led hunts using endpoint, identity, network and cloud evidence with documented findings and limitations.

Typical deliverables

  • Hunt hypotheses
  • Query and evidence pack
  • Exposure findings
  • Detection recommendations

Intended outcomes

  • Suspicious activity assessed
  • Improved detections
  • Analyst learning
Typical deliverables

What an engagement may produce.

  • ✓ Hunt hypotheses
  • ✓ Query and evidence pack
  • ✓ Exposure findings
  • ✓ Detection recommendations
Intended outcomes

What the work is designed to improve.

  • ✓ Suspicious activity assessed
  • ✓ Improved detections
  • ✓ Analyst learning
Plan the right scope

Connect the requirement to business context.

We will help clarify the objective, dependencies, authorised activity and useful evidence.

Start a conversation