Straight answer
Ask two questions per high-weight criterion and one per low-weight criterion. The twelve below follow the rubric on this site: data reach, intel-to-detection speed, continuous hunting, time to first value, ATT&CK coverage, rule lifecycle and buyer transparency. For each, we say what a clear answer contains.
Why start from the criteria
The matrix on this site scores six tools on seven criteria, each from 1 to 5, using only what vendors publish. A demo is the place to fill in what public pages leave out. Every score reason on the matrix that says "not described" or "not stated" is a question worth asking in person.
The questions are grouped by criterion and ordered by weight, so the criteria that count most toward the weighted figure come first. If your priorities differ from ours, reorder them. The weights and the reasoning behind them are on How we compare.
Data reach without new ingestion (weight 25%)
- Which of our current data platforms can you query where the data already sits, and which would you need to copy or ingest? Ask the vendor to name them against your own list: SIEM, EDR, identity provider, cloud logs, data lake and object storage. A clear answer separates "queried in place" from "ingested" platform by platform. Some vendors publish this split on their connector pages; if they do, bring the page to the call.
- Where do hunt and detection queries run, and who pays for the compute? When a tool queries a data lake or a SIEM in place, the query uses that platform's resources. A clear answer says which platform executes the query and how the vendor limits query volume.
Intel-to-detection speed (weight 20%)
- Take a threat advisory published this week and show us the path to a deployed rule. Watch for each step: reading the advisory, extracting behaviours or indicators, writing the query in each platform's own language, testing it, and deploying it. Note which steps are automatic and which need an analyst.
- How is a new rule tested before it goes live, and against how much of our own data? Some vendors state a backtest window on public pages. Ask for the window, what happens when a rule matches too much, and whether the result is shown to the analyst before deployment.
Continuous hunting (weight 20%)
- Which hunts run without anyone asking, and on what schedule? A clear answer names the trigger: new intelligence, a hypothesis library, a daily schedule, or a mix. Ask to see a hunt that ran last week without a request.
- What does an analyst receive when a hunt finds something? Ask to see the output itself: a list of events, a written summary, a case, or a proposed detection. Ask whether each step of the hunt is shown so the analyst can check the reasoning.
Time to first value (weight 15%)
- What has to happen before our first hunt runs on our own data? Ask for the list of setup tasks, who does each one, and whether any of them is a new ingestion pipeline. A vendor that states a setup time on its public pages should be able to show what fits inside it.
- How is the product bought and deployed? SaaS, a marketplace listing, or a deployment in your own cloud each change procurement and security review. Ask which certifications and listings exist today.
Coverage measurement against ATT&CK (weight 8%)
- Show us how you measure our coverage against MITRE ATT&CK. A clear answer is a view, not a claim: techniques or tactics, which rules map to each, and where the gaps are. ATT&CK v19 has 15 Enterprise tactics, so ask whether the view reflects the current version.
Rule lifecycle (weight 7%)
- Where does a rule live after deployment, and how do we see its history? Ask about version history, review and approval, export to your own repository, and rollback. Ask to see one rule's change history.
Buyer transparency (weight 5%)
- What can our team read or try before the next call? Public documentation, a sandbox, a cost tool or a full connector list all let a buyer check claims without a sales cycle. None of the six vendors we compare publishes a price, so ask how pricing is calculated.
- Which of the answers above can you confirm in writing? Anything said in a demo that is not on a public page is worth having in an email or the order form.
Using the answers
Score each answer against the same 1 to 5 levels we use, then apply your own weights. The lesson Building a shortlist from this matrix shows one way to do that.
Sources
- https://threathuntingcompare.com/matrix
- https://threathuntingcompare.com/how-we-compare
- https://attack.mitre.org/tactics/enterprise/
- https://artemissecurity.com/connectors/
- https://www.anvilogic.com/calculator
Editorial assessment · Desk research from public vendor material, last reviewed September 2026