Cybatar Security Hub
Threat Hunting / Hunt lifecycle
Threat-hunting guide

Threat Hunting Lifecycle: Requirement to Detection Improvement

What should happen before and after a threat hunt?

Direct answer

A durable hunt lifecycle starts with a requirement or signal, forms a bounded hypothesis, verifies the required telemetry, executes and records the hunt, escalates suspicious findings, captures negative/uncertain results honestly, and feeds lessons into detection engineering, intelligence requirements and telemetry-gap remediation.

Reference basis

Cybatar first-party methodology informed by NIST SP 800-150 and MITRE ATT&CK — Threat hunting operating lifecycle

The lifecycle is Cybatar-authored. NIST SP 800-150 informs threat-information use and sharing; MITRE ATT&CK can inform adversary-behaviour hypotheses. Neither source certifies this lifecycle.

External reference →

Hunt method

Step 1

Requirement or trigger

Start from intelligence, an incident lesson, a detection gap, a material exposure or a change in adversary behaviour.

Step 2

Hypothesis and scope

Define the behaviour, assets/identities, time window, expected evidence and exit/escalation criteria.

Step 3

Telemetry readiness

Confirm source availability, retention, parsing, timestamps, identities and known blind spots before interpreting absence of evidence.

Step 4

Execute and preserve evidence

Run queries, record observations and pivots, preserve relevant artefacts and maintain a reproducible decision trail.

Step 5

Operationalise the result

Create an incident, detection improvement, intelligence update, exposure treatment or telemetry remediation action and track it to closure.

Relevant Cybatar sources

Claim boundary

This lifecycle is a Cybatar-authored operating model, not an external threat-hunting standard or certification. Hunt maturity should be assessed from evidence and outcomes rather than the existence of a documented lifecycle.

These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.