Next lesson
The data a hunt reads, and why reach matters most here
The five kinds of data most hunts read, the difference between querying data in place and copying it first, and why this site weights data reach at 25%.
Lesson
Basics · Lesson 1 of 3 · 3 min read
Straight answer
Threat hunting is looking for attacker activity that no detection rule has flagged yet. Alert triage handles alerts that rules have already raised, and detection engineering writes and maintains those rules. The tools on this site connect the three: a hunt that finds something becomes a rule, and new intelligence can start either.
A security operations team does three related jobs. Triage works through alerts that existing rules have raised and decides which need action. Detection engineering designs, writes, tests and maintains those rules. Hunting starts from a question instead of an alert: is this behaviour happening in our data, even though nothing has fired?
The three feed each other. A hunt that finds real activity usually ends with a new or improved detection rule, so the same activity raises an alert next time. A rule that fires too often sends work back to detection engineering. New threat intelligence can start either job: a hunt for the behaviour a report describes, or a rule to catch it from now on.
Most hunts start in one of two ways. An intelligence-led hunt begins with a published report or advisory, for example from CISA, and looks for the behaviour it describes in your own data. A hypothesis-led hunt begins with a stated guess, such as a technique that may be in use, and looks for evidence for or against it. MITRE ATT&CK is the shared vocabulary for both: it lists adversary tactics, the goal at each stage of an attack, and techniques, the ways those goals are reached.
The vendors on this site describe both starting points. Mars Security describes converting threat intelligence into behavioral hunts and introduced hypothesis playbooks in September 2026. Nebulock's published LOCK framework starts each hunt from a hypothesis mapped to ATT&CK. Vega runs the whole hunt when given a hypothesis. Artemis Security runs hunts daily against a library and more than 100 intelligence feeds.
Hunting was long a manual job: an analyst picked a question, wrote a query for each data source and read the results. That limits how many hunts a team can run. The tools compared here use automation and AI agents to run hunts without a person starting each one, on a schedule or when new intelligence arrives. That is what this site scores as continuous hunting.
Automation does not remove the analyst. Several vendors describe handing an analyst a shortlist or a written finding rather than a raw result, and some show each step of the hunt so the reasoning can be checked. When you compare tools, ask what arrives on the analyst's desk and how much of the work behind it is visible.
A hunt can only find what its data can show. Endpoint activity, sign-ins, cloud audit logs and network records each answer different questions. The next lesson, The data a hunt reads, walks through the usual sources and explains why this site gives the most weight to reaching them without a new ingestion pipeline.
Next lesson
The five kinds of data most hunts read, the difference between querying data in place and copying it first, and why this site weights data reach at 25%.
Editorial assessment · Desk research from public vendor material, last reviewed September 2026