Begin with a bounded hypothesis that states what adversary behaviour may be present, why it is plausible in the environment, which assets or identities are in scope, what telemetry could support or refute the hypothesis, and what result will trigger escalation, tuning or closure. A hunt should not begin as an unbounded search for “anything suspicious.”
Reference basis
MITRE ATT&CK provides a knowledge base of adversary tactics and techniques. ATT&CK can help structure behaviours to investigate, but an ATT&CK mapping is not proof that an adversary is present or that a hunt is effective.
External reference →Hunt method
State the hypothesis
Describe the suspected behaviour, affected environment and reason for concern in a form that can be supported or refuted.
Map required telemetry
Identify the endpoint, identity, cloud, network, application or other evidence needed and verify source health before querying.
Define scope and time window
Bound the hunt by assets, users, services, geography, technology and time to avoid an investigation that can never be completed.
Record observations and pivots
Keep query logic, results, pivots, excluded explanations and evidence references so another analyst can reproduce the reasoning.
Close with an outcome
Escalate confirmed suspicious activity, improve a detection, create a telemetry-gap finding, update intelligence or close the hypothesis with documented limitations.
Relevant Cybatar sources
Claim boundary
A completed hunt does not prove the absence of compromise. Hunt results are limited by hypothesis quality, scope, telemetry completeness, retention, query logic and analyst judgement.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.