Hunted by investigators
Hunts are designed and run by DFIR consultants. The hypotheses come from how intrusions actually progress: initial access, credential theft, lateral movement and persistence on the systems that matter.
Managed engagement / 04
Assurance, every month, that the systems that matter are not compromised, proven with the evidence examined.
Designed and run by DFIR consultants, so the hunts start from how compromises actually unfold, and every detection is investigated with forensic techniques to a verdict: compromise, or cleared with the evidence that clears it.
Placed where a compromise would matter most, on the critical workloads and the infrastructure they depend on in IT and OT, with new hunts added when the threat or the estate changes.
A hunt is only as good as the person who wrote it and the depth at which its findings are followed. These three are fixed for every engagement.
Hunts are designed and run by DFIR consultants. The hypotheses come from how intrusions actually progress: initial access, credential theft, lateral movement and persistence on the systems that matter.
Each detection is investigated on the host with forensic techniques, through the Velociraptor agent deployed on the endpoints in scope. A lead closes as compromise or as cleared, with the evidence that decided it written down.
Hunts are placed on the critical workloads, Tier 0 identity and the infrastructure they depend on. The hunt catalog changes when the threat or the estate changes, so every hunt earns its place.
Scope
The hunt plan starts from the critical workloads and infrastructure, and from the techniques current detection does not cover.
How it is tooled
Each engagement uses the tooling that fits the environment, and every detection is investigated to the same high level of confidence before it is called compromise or cleared.
How a cycle runs
The survey and the coverage map are built at onboarding and kept current. The hunts, the triage and the report run every cycle.
Endpoints, servers, log sources, crown jewels and high-value accounts, refreshed whenever the estate changes.
Existing detection use-cases mapped to MITRE ATT&CK, to find the techniques current monitoring does not cover.
Core hunts every month against the gaps that matter most, and intelligence-driven hunts when an active campaign targets your sector, region or technology.
Each hunt is a written hypothesis with the evidence it requires. Findings are triaged crown jewels and Tier 0 first, and an active compromise goes to your incident response team immediately.
A monthly report and debrief, the assurance statement, an updated coverage map, and new real-time detection use-cases for your team to run.
Building the capability
Threat Hunting Capability Review & Enhancement reviews an existing hunting function and builds what it runs on, in five stages. It suits a SOC that will hunt with its own people.
Processes, tools, data sources and integration with SOC workflows, with each gap classified as data source, automation, scope or expertise.
A threat hunting charter with escalation paths and OT safety constraints, plus KPIs and a maturity roadmap.
A hunt calendar and a hunt catalog drawn from your threat landscape and business context.
Hunt playbooks: scope, hypothesis, ATT&CK technique, existing detection, evidence required and its quality, analytics and triage logic.
Hunt-level, weekly operational and monthly strategic reporting, with OT-specific reporting where OT is in scope.
Deliverables
Every conclusion states what was examined and what it supports. Where the evidence does not settle a question, that is written down.
Who this is for
What is needed to scope it
Scoping starts with a conversation, not a questionnaire. If hunting is the wrong instrument for the question, that is said plainly at the first call.
NEXT / RELATED SERVICE
Compromise AssessmentWhen the question needs one answer across the whole estate, now.
NEXT / SCOPING
EngageDescribe the situation. The call is with the consultant who would run the hunts, not a salesperson.