TechKnowSurge
NIST NICE K1269 CompTIA CySA+ 1.4 CompTIA Security+ 4.4 NIST 800-53 SI-4 NIST 800-53 RA-10 NIST CSF DE.AE-07 CompTIA SecurityX 2.6
VideoSecurityFree

Threat Hunting

Threat hunting is the practice of having a human analyst actively search network devices, logs, and traffic for indicators of compromise that automated monitoring systems may miss. This topic covers how threat hunting compares to SIEM-based monitoring and how both relate to vulnerability scanning and penetration testing.

Complete this video to capture a CTF flag worth 1 point.

About this video

Automated monitoring tools, including SIEM platforms, provide essential visibility into network activity by aggregating logs and alerting on known indicators of compromise. However, automation has a fundamental limitation: a sophisticated attacker who gains access to a network can manipulate or destroy log data, effectively blinding these systems. Threat hunting exists to close that gap by deploying trained human analysts to manually examine network devices, traffic flows, and logs in search of compromise indicators that automated tools failed to surface. The relationship between threat hunting and SIEM monitoring mirrors the relationship between penetration testing and vulnerability scanning. Vulnerability scanners identify weaknesses through automated analysis, while penetration testers use human skill and judgment to actually exploit them. In the same way, a SIEM handles automated detection of compromises, while threat hunters take on the human-driven side of that same problem. Both pairings reflect a recognition that software and human expertise serve complementary roles in a mature security program. A key attribute of threat hunting is that it is proactive. Rather than waiting for an alert to signal that something is wrong, threat hunters go looking for evidence of compromise on their own initiative. This distinguishes threat hunting from purely reactive incident response, where action is triggered by a known event. By actively searching the environment before any alarm is raised, threat hunters can uncover threats that might otherwise persist undetected for extended periods.

What you'll learn

What's covered

Threat Hunting & Monitoring

Aligned to

NIST NICE
K1269 Knowledge of security information and event management (SIEM) tools and techniques
CompTIA CySA+
1.4 Compare and contrast threat-intelligence and threat-hunting concepts.
CompTIA Security+
4.4 Explain security alerting and monitoring concepts and tools.
NIST 800-53
SI-4 System Monitoring
RA-10 Threat Hunting
NIST CSF
DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis.
CompTIA SecurityX
2.6 Explain how threat and vulnerability management techniques are used in the enterprise.

Key terms

Security Information and Event Management
SIEM
A system that aggregates and analyzes security event data from across an organization to detect and respond to threats.
Threat Hunting
Threat hunting is a proactive security practice in which analysts actively search for signs of adversary activity that has evaded automated detection, using hypotheses driven by threat intelligence and behavioral anomalies.
Indicators of Compromise
IoC
Indicators of Compromise are forensic artifacts such as file hashes, IP addresses, domain names, and registry keys that provide evidence a system may have been compromised, enabling threat detection and intelligence sharing.
Log Management
The process of collecting, storing, analyzing, and monitoring log data generated by systems and applications.
Threat Intelligence
Information about existing or emerging threats that helps organizations make informed security decisions.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.

Topics

Threat Hunting Siem Indicators Of Compromise Cybersecurity Vulnerability Scanning Penetration Testing

Transcript

Hopefully we're going to set up a robust monitoring system, something that's monitoring many different aspects of our network. But even so, those monitoring systems don't always catch everything, and for that maybe we do some sort of threat hunting.

Let's say we have a monitoring system that's monitoring a lot of the devices within our network and a lot of our network links and traffic throughout our network. Maybe it's fairly robust, but the problem is that somebody who's going to compromise your system might go in and be able to circumvent this log information, or maybe even attack the logging server and remove some of those logs. So an automated system is not necessarily going to catch everything. What threat hunting is, is an actual person going and looking at the individual equipment, the individual logs, the individual links within the network, and doing some threat hunting, looking for threats that are on the network. This is looking for the indicators of compromise, indicators that something has happened on these different devices.

Monitoring, threat hunting, and pen testing

Let's look at monitoring versus threat hunting, and we'll also compare it to pen testing, because I see some similarities when it comes to vulnerabilities. When it comes to compromises, if we are using software to monitor those systems, we are using something like a SIEM. A SIEM is going to go through and aggregate those logs and be able to look for certain things that are happening on our systems, looking for indicators of compromise and alerting off of those. But if we are going to do it in person, that is threat hunting.

It's very similar to vulnerabilities. We've got vulnerability scanners that look for those vulnerabilities within our network, and then we have pen testing, which is somebody actually trying to penetrate our network, somebody actually trying to test out and find those vulnerabilities. So pen testing is done by a person versus vulnerability scanning done by software. Same thing with compromises: when it comes to compromises on your network, a SIEM hopefully recognizes those from an automated standpoint, but where the automation fails us, threat hunting picks up, where there's an actual person looking at that.

Threat hunting as proactive

One last thing that I will address with threat hunting is this word proactive. Threat hunting is proactively looking for compromised systems. A lot of people, some people, have an issue with this word proactive, and maybe I do a little bit as well. Threat hunting is considered being proactive in that you're not just waiting around for an alert to happen; instead you're taking a proactive stance and going and looking for those compromises on your network. Where I think there's some confusion is that there's some consideration that proactive is all the stuff that happens before a compromise and reactive is you're reacting to the compromise. But in essence, what we're talking about here is that you are taking a proactive stance: before you get notified from any monitoring system that there's an issue, you're going out there and looking for those issues.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →