Threat hunting is the practice of having a human analyst actively search network devices, logs, and traffic for indicators of compromise that automated monitoring systems may miss. This topic covers how threat hunting compares to SIEM-based monitoring and how both relate to vulnerability scanning and penetration testing.
Threat Hunting & Monitoring
Hopefully we're going to set up a robust monitoring system, something that's monitoring many different aspects of our network. But even so, those monitoring systems don't always catch everything, and for that maybe we do some sort of threat hunting.
Let's say we have a monitoring system that's monitoring a lot of the devices within our network and a lot of our network links and traffic throughout our network. Maybe it's fairly robust, but the problem is that somebody who's going to compromise your system might go in and be able to circumvent this log information, or maybe even attack the logging server and remove some of those logs. So an automated system is not necessarily going to catch everything. What threat hunting is, is an actual person going and looking at the individual equipment, the individual logs, the individual links within the network, and doing some threat hunting, looking for threats that are on the network. This is looking for the indicators of compromise, indicators that something has happened on these different devices.
Let's look at monitoring versus threat hunting, and we'll also compare it to pen testing, because I see some similarities when it comes to vulnerabilities. When it comes to compromises, if we are using software to monitor those systems, we are using something like a SIEM. A SIEM is going to go through and aggregate those logs and be able to look for certain things that are happening on our systems, looking for indicators of compromise and alerting off of those. But if we are going to do it in person, that is threat hunting.
It's very similar to vulnerabilities. We've got vulnerability scanners that look for those vulnerabilities within our network, and then we have pen testing, which is somebody actually trying to penetrate our network, somebody actually trying to test out and find those vulnerabilities. So pen testing is done by a person versus vulnerability scanning done by software. Same thing with compromises: when it comes to compromises on your network, a SIEM hopefully recognizes those from an automated standpoint, but where the automation fails us, threat hunting picks up, where there's an actual person looking at that.
One last thing that I will address with threat hunting is this word proactive. Threat hunting is proactively looking for compromised systems. A lot of people, some people, have an issue with this word proactive, and maybe I do a little bit as well. Threat hunting is considered being proactive in that you're not just waiting around for an alert to happen; instead you're taking a proactive stance and going and looking for those compromises on your network. Where I think there's some confusion is that there's some consideration that proactive is all the stuff that happens before a compromise and reactive is you're reacting to the compromise. But in essence, what we're talking about here is that you are taking a proactive stance: before you get notified from any monitoring system that there's an issue, you're going out there and looking for those issues.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →