Straight answer

Threat hunting is looking for attacker activity that no detection rule has flagged yet. Alert triage handles alerts that rules have already raised, and detection engineering writes and maintains those rules. The tools on this site connect the three: a hunt that finds something becomes a rule, and new intelligence can start either.

Where hunting sits next to triage and detection

A security operations team does three related jobs. Triage works through alerts that existing rules have raised and decides which need action. Detection engineering designs, writes, tests and maintains those rules. Hunting starts from a question instead of an alert: is this behaviour happening in our data, even though nothing has fired?

The three feed each other. A hunt that finds real activity usually ends with a new or improved detection rule, so the same activity raises an alert next time. A rule that fires too often sends work back to detection engineering. New threat intelligence can start either job: a hunt for the behaviour a report describes, or a rule to catch it from now on.

Where does a hunt start?

Most hunts start in one of two ways. An intelligence-led hunt begins with a published report or advisory, for example from CISA, and looks for the behaviour it describes in your own data. A hypothesis-led hunt begins with a stated guess, such as a technique that may be in use, and looks for evidence for or against it. MITRE ATT&CK is the shared vocabulary for both: it lists adversary tactics, the goal at each stage of an attack, and techniques, the ways those goals are reached.

The vendors on this site describe both starting points. Mars Security describes converting threat intelligence into behavioral hunts and introduced hypothesis playbooks in September 2026. Nebulock's published LOCK framework starts each hunt from a hypothesis mapped to ATT&CK. Vega runs the whole hunt when given a hypothesis. Artemis Security runs hunts daily against a library and more than 100 intelligence feeds.

Why did continuous hunting become its own category?

Hunting was long a manual job: an analyst picked a question, wrote a query for each data source and read the results. That limits how many hunts a team can run. The tools compared here use automation and AI agents to run hunts without a person starting each one, on a schedule or when new intelligence arrives. That is what this site scores as continuous hunting.

Automation does not remove the analyst. Several vendors describe handing an analyst a shortlist or a written finding rather than a raw result, and some show each step of the hunt so the reasoning can be checked. When you compare tools, ask what arrives on the analyst's desk and how much of the work behind it is visible.

What does a hunt need from your data?

A hunt can only find what its data can show. Endpoint activity, sign-ins, cloud audit logs and network records each answer different questions. The next lesson, The data a hunt reads, walks through the usual sources and explains why this site gives the most weight to reaching them without a new ingestion pipeline.

Related

Editorial assessment · Desk research from public vendor material, last reviewed September 2026