Detection waits.
Hunting looks.
The hypothesis is “an attacker would have used this technique”, and we interrogate the telemetry for exactly that. We hunt across endpoint, identity and cloud data for traces of current or past compromise, and hand every confirmed hypothesis back to your SOC as a detection rule.
What is included.
Actively looking for what your alerts never raised.
Hypotheses
Derived from the threat landscape, your sector and your recent assessments — not from a generic list.
Data access
Connection to EDR, SIEM and cloud logs; a check on whether the required telemetry exists at all.
Hunt
Queries per hypothesis, investigation of anomalies, verification of findings.
Handback
Confirmed techniques as detection rules; missing telemetry as a backlog; findings escalated as incidents.
Five steps,
one deliverable.
Hypotheses
Selection and prioritisation with your team.
Access
Connect data sources, note missing telemetry.
Hunt
Query, investigate, verify.
Escalation
Move findings into incident response.
Handover
Rules, backlog, report.