Proactive practice in which analysts actively search for signs of compromise within a network before any automated alert surfaces them.
Threat hunting starts from the premise that an attacker may already be present in a network without having triggered any automated alert, notably via living-off-the-land or APT techniques. The hunter formulates hypotheses about the probable tactics, techniques and procedures of an adversary, then tests them by querying logs, endpoint telemetry and network data. The approach is fundamentally human and iterative, complementing automated tooling. It relies on frameworks such as MITRE ATT&CK to structure hypotheses. For cyber insurers, the presence of an internal or contracted threat-hunting capability is a security maturity indicator that can justify a premium reduction or lower deductible. Threat hunting also reduces the attacker's average dwell time, the main variable driving loss severity. In AI environments, threat hunting extends to searching for anomalous behavior in inference pipelines or unexplained model drift not accounted for by legitimate data changes.
Following the publication of a threat intelligence report signaling a campaign targeting European insurers, a hunt team spends three days searching for the associated IoCs (indicators of compromise) across infrastructure logs. No incident is confirmed, but the exercise is documented and shared with the cyber insurer at renewal as proof of reasonable diligence.
chasse aux menaces, threat hunting, hunt team, proactive threat detection