Retain the hypothesis and rationale, analyst and approval context, scope and time window, required telemetry and source-health evidence, query or analytic logic, observations, pivots, false explanations considered, linked artefacts, outcome, limitations and any incident, detection, intelligence or telemetry-gap action created from the hunt.
Reference basis
The evidence model is authored by Cybatar. ATT&CK is used only as an external behavioural reference where applicable and does not prescribe this evidence model.
External reference →Hunt method
Preserve the hypothesis
Record the question before the result so later reviewers can distinguish a planned hunt from retrospective storytelling.
Preserve source health
Record which telemetry was available, its retention and any parser, clock, identity or collection gaps that limit the conclusion.
Preserve query logic
Store queries, filters, enrichment assumptions, time zones and relevant versions so results can be reproduced.
Preserve analytical pivots
Document why the analyst expanded or narrowed scope and which benign explanations were checked.
Preserve outcome and limitations
Link incidents, detections, intelligence updates or telemetry findings and state what the hunt did not test.
Relevant Cybatar sources
Claim boundary
Reproducible hunt evidence strengthens reviewability but does not prove the environment was fully searched, that telemetry was complete or that an adversary was absent.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.