A durable hunt lifecycle starts with a requirement or signal, forms a bounded hypothesis, verifies the required telemetry, executes and records the hunt, escalates suspicious findings, captures negative/uncertain results honestly, and feeds lessons into detection engineering, intelligence requirements and telemetry-gap remediation.
Reference basis
The lifecycle is Cybatar-authored. NIST SP 800-150 informs threat-information use and sharing; MITRE ATT&CK can inform adversary-behaviour hypotheses. Neither source certifies this lifecycle.
External reference →Hunt method
Requirement or trigger
Start from intelligence, an incident lesson, a detection gap, a material exposure or a change in adversary behaviour.
Hypothesis and scope
Define the behaviour, assets/identities, time window, expected evidence and exit/escalation criteria.
Telemetry readiness
Confirm source availability, retention, parsing, timestamps, identities and known blind spots before interpreting absence of evidence.
Execute and preserve evidence
Run queries, record observations and pivots, preserve relevant artefacts and maintain a reproducible decision trail.
Operationalise the result
Create an incident, detection improvement, intelligence update, exposure treatment or telemetry remediation action and track it to closure.
Relevant Cybatar sources
Claim boundary
This lifecycle is a Cybatar-authored operating model, not an external threat-hunting standard or certification. Hunt maturity should be assessed from evidence and outcomes rather than the existence of a documented lifecycle.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.