secureskies
Cyber Security/Respond/Threat Hunting

Detection waits.
Hunting looks.

The hypothesis is “an attacker would have used this technique”, and we interrogate the telemetry for exactly that. We hunt across endpoint, identity and cloud data for traces of current or past compromise, and hand every confirmed hypothesis back to your SOC as a detection rule.

FormatHunt cycleone-off or quarterly
DataEDR · Entra ID/AD logsM365 · AWS/Azure logs
ModelMITRE ATT&CKhypothesis-driven
OutcomeHunt reportplus new detection rules
01 · Service

What is included.

Actively looking for what your alerts never raised.

Hypotheses

Derived from the threat landscape, your sector and your recent assessments — not from a generic list.

Data access

Connection to EDR, SIEM and cloud logs; a check on whether the required telemetry exists at all.

Hunt

Queries per hypothesis, investigation of anomalies, verification of findings.

Handback

Confirmed techniques as detection rules; missing telemetry as a backlog; findings escalated as incidents.

02 · Process

Five steps,
one deliverable.

01

Hypotheses

Selection and prioritisation with your team.

02

Access

Connect data sources, note missing telemetry.

03

Hunt

Query, investigate, verify.

04

Escalation

Move findings into incident response.

05

Handover

Rules, backlog, report.

03 · Who it fits

When this service
applies.

Companies with EDR/SIEM but no hunting capacity
After an incident, to check for remaining access
Before a merger or acquisition, as a baseline of the target environment
More services · Respond

What sits in your telemetry
that no alert covers?