What Is Threat Hunting?
Video coming soon
I want to give you a baseline understanding of threat hunting, and why it matters when designing security agents.
I want to hit four specific notes.
First, I'll show you what most security looks like today — the orthodox, alert-based approach.
Then I'll show you where that approach breaks down, and importantly, what threat hunting does differently.
Then I'll explore a question you might be asking: if hunting is so much better, why is it still the heterodox practice?
And finally, I'll make the argument for the agentic layer: that the thing holding hunting back was never the idea, and that an agentic layer is what lets the idea reach the potential it always had.
The Status Quo: Alert-Based Security
Strip most defensive security down to its skeleton and you get the five steps below. Not every environment matches this exactly, but it's a good archetype — it captures enough of the common shape to be useful.
It starts with telemetry. Sensors all over the estate — on endpoints, on the network, in the cloud, in the identity provider — record what happens and send it on.
Next comes processing. All of that telemetry is forwarded to one central place, usually the SIEM, where it gets cleaned up before anything looks at it: duplicates removed, formats normalized so that a login from one system looks like a login from another, timestamps aligned, etc.
Then detection. A large battery of detections runs against the processed data. Each detection is a pattern someone wrote in advance — a known bad hash, a known malicious domain, a login pattern that's impossible travel — and the data is checked against every one of them.
When a detection matches, it raises an alert. That's the moment the machine says "this looks like the thing I was told to look for," and the alert goes into a queue.
Finally, review. A human analyst picks the alert up from the queue, looks at the evidence behind it, and makes the call: true positive — this is real, do something — or false positive — the pattern matched, but it's harmless.
It's easy to poke holes in this process, but there's a good reason it's built the way it is. Machines are extraordinary at processing and signature-matching at scale; humans are extraordinary at judgment. So you lean on each for what it's best at: machines do the volume, humans make the call.
There Is a Problem
There's a fundamental problem with this approach, and the cleanest way to see it is a thought experiment I'm borrowing from Rob Lee at SANS — the deer with a mustache.
You take a person out to a forest, set them up in a hide, and give them one job: if you see a deer walk by, radio it in.
A deer walks by. They key the radio: "deer."
A while later a second deer walks by — but this one has a mustache. They radio it in anyway: "deer." Obviously. It's a deer; it just has something odd going on.
Now give the same job to a signature-based detection. It has a signature for "deer," so when the plain deer walks by, it matches — "deer," radioed in.
Then the deer with the mustache walks past. Nothing, just silence. It doesn't match the signature, so the detection never recognizes it as a deer at all. Nothing gets radioed in.
Obviously we don't care about literal deer — we care about known threats. A "deer with a mustache" is a known threat that has been altered: the same malware with a repacked hash, the same beacon on a new port, the same technique with one step swapped out.
And alterations like that aren't the exception — they're standard practice for any halfway-competent threat actor. That's the whole point: a detection misses anything even slightly off from the pattern it was written to match.
The Fundamental Tension
You might respond: surely this is an easy problem to solve? Don't just match "deer" — match the deer plus every conceivable variation: the deer with a mustache, the deer with a sombrero, the deer with sunglasses, the purple deer, the deer with twelve legs.
But relaxing the pattern match creates a bigger — possibly worse — problem: the false-positive deluge. Yes, you will now alert on the real threat — but it will be buried under so many false positives that the system becomes functionally useless.
This captures the fundamental tension at the heart of alert-based security:
Too strict
You miss slight variations. Brittle — false negatives.
Too relaxed
You drown in false positives. Noisy.
You trade a system that misses real threats for one that buries the true positives under so many false ones that finding them is practically impossible. Tuning that dial well — finding the local optimum for your environment — is one of the foundational problems you have to solve in organizational security.
Alert-Based Is Low Resolution
There's another way to frame all of this: alert-based detection is low resolution. Look at just the alert step and notice that it's binary — two outcomes. It can not alert (in which case the analyst never even learns the thing existed), or it can alert (in which case the analyst gets to review and make a call).
But conceptually, between "don't alert" and "alert," there's a whole spectrum of states the binary simply can't represent:
ALERT
All of those in-between states — the shades of nuance that don't fit squarely into alert-or-not, and yet are exactly the early breadcrumbs that lead to either — have, up to now, been the domain of human judgment.
So, What Is Threat Hunting?
It's exactly bringing those nuanced shades into detection — the human judgment — that allows us to formulate a definition of threat hunting:
Threat hunting is the process of bringing human judgment into the detection process itself — not just into reviewing its output.
Instead of waiting at the end of the pipeline to review whatever the machines alerted on, the hunter goes upstream and works in that nuanced middle — chasing the "something feels off" that no signature would ever fire on.
Why? Because it gives us a higher-resolution lens for finding threats compared to alerting alone. You catch the things signature-based detection structurally cannot — the deer with a mustache.
But I do want to mention something important — threat hunting is not just about finding threats. Finding threats is the method. The goal is broader — improving your overall security posture: the coverage gaps a hunt exposes, the new detections you write from it, the understanding of your own environment you build along the way. (David Bianco has a great talk on exactly this.)
The Main Limitation
But if all this is true, if threat hunting is so amazing, it begs the question — why hasn't it become the established paradigm for organizational defensive programs?
As I pointed out earlier, the secret sauce at the heart of threat hunting is human judgment, and the problem is — human judgment does not scale. A single hunter can only hold so much in their head, chase so many hunches, look at so much data. Meanwhile a single day of enterprise telemetry dwarfs anything a person could ever sift by hand.
The very quality that makes threat hunting powerful — that it runs on a human's nuanced, ambiguity-tolerant judgment — is also its hard ceiling. There is a fundamental asymmetry between the scale of the detection requirement and what human judgment offers.
The Central Premise
That's the gap. In my opinion it's not that threat hunting was the wrong idea, it's simply that it did not have the required technology to fully realize its promise.
An agentic layer can help close that gap — to take the judgment that used to live only in a hunter's head and give it reach, so one hunter can cover ground that used to take a team weeks.
How? Because for the first time we have an agentic layer — a layer that is itself capable of reasoning.
It doesn't map one-to-one onto human reasoning. It's different — better in some ways, not as good in others — but it's a form of reasoning nonetheless. It isn't bounded to pre-programmed answers; it carries the potential to work through problems it has never encountered.
And that is the central premise of agent-assisted threat hunting. The system adopts threat hunting's proactive, behavior-based approach — the powerful part — and mitigates its main limitation, the scarcity of human judgment, by carefully integrating an agentic layer that contributes its own form of judgment and reasoning.
Not to replace the hunter's judgment — to extend it, and to scale it.
Ready to master agents for defensive security?
Start mastering agents for defensive security with my flagship, self-paced online course, designed specifically for defenders.
Follow a structured path from understanding agents to using them in your own environment.
What’s included
- 120+ lessons
- Hands-on labs
- Build It Yourself guides
- Lifetime course access
- Course updates included
- One-time purchase
Stay in the loop
Keep learning. Keep building.
I regularly publish free educational content to help you master agents for defensive security. Join the list for new articles, videos, and course drops.
I’ll only email you when there’s something genuinely worth your time. No spam. No automated marketing flows.
References1
- Achieving PEAK Performance: Introducing the PEAK Threat Hunting Framework. David Bianco's talk on what a hunt produces beyond the find itself: new detections, exposed coverage gaps, environment knowledge. youtube.com ↗