# What is Threat Hunting?

> Threat hunting is a proactive, evidence-driven search for malicious activity that existing controls have not already surfaced with sufficient confidence.

- Canonical URL: https://yellowcube.eu/glossary/threat-hunting/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

A hunt usually begins with a testable hypothesis, suspicious pattern, intelligence lead, or known visibility gap, then examines relevant endpoint, identity, network, cloud, or application evidence.

Hunting is valuable even when it finds no compromise, provided the search was well scoped and its assumptions were tested. It can expose missing telemetry, weak investigation paths, unsafe configurations, or opportunities for new detections. Repeated, aimless querying without a question, method, or documented outcome is not a mature hunting practice.

### Key points

- **Starting points:** Adversary behaviors, changes in risk, incident lessons, anomalies, threat intelligence, and questions that automated analytics cannot answer reliably.
- **Typical workflow:** Form a hypothesis, define required evidence, check data quality, search and pivot, validate findings, record conclusions, and feed improvements back into controls.
- **Useful outcomes:** Confirmed or ruled-out activity, new detection logic, improved telemetry, documented baselines, and clearer response playbooks.
- **Important limitation:** A hunt can only examine the evidence available to it. No findings does not prove that the environment is uncompromised, especially where collection or retention is incomplete.

### Related terms

[Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>)

### Sources

[NIST SP 800-172 Rev. 3](https://csrc.nist.gov/pubs/sp/800/172/r3/final) · [MITRE ATT&CK threat-hunting training](https://attack.mitre.org/resources/learn-more-about-attack/training/threat-hunting/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

