Hunt a testable hypothesis, preserve the evidence, improve the system
Threat hunting should have a defined question, verified telemetry, bounded scope, reproducible analysis and an operational outcome—not an open-ended search for suspicious activity.
Hypothesis-driven hunting
Begin with a bounded hypothesis that states what adversary behaviour may be present, why it is plausible in the environment, which assets or identities are in scope, what telemetry could support or refute the hypothesis, and what result will trigger escalation, tuning or closure. A hunt should not begin as an unbounded search for “anything suspicious.”
Open guide →Hunting guideHunt evidence
Retain the hypothesis and rationale, analyst and approval context, scope and time window, required telemetry and source-health evidence, query or analytic logic, observations, pivots, false explanations considered, linked artefacts, outcome, limitations and any incident, detection, intelligence or telemetry-gap action created from the hunt.
Open guide →Hunting guideHunt lifecycle
A durable hunt lifecycle starts with a requirement or signal, forms a bounded hypothesis, verifies the required telemetry, executes and records the hunt, escalates suspicious findings, captures negative/uncertain results honestly, and feeds lessons into detection engineering, intelligence requirements and telemetry-gap remediation.
Open guide →Threat intelligence
Define requirements, preserve IOC context and separate analytical confidence from observation.
Threat intelligenceDetection engineering
Turn repeatable hunting knowledge into validated detections with telemetry prerequisites and test evidence.
Detection engineeringMethodology
Read the Cybatar intelligence and hunting principles and explicit non-claims.
Read methodology