SOC / SOC-06
Proactive compromise investigation — threat hunting
Search for suspicious behaviour using explicit hypotheses beyond existing alerts. Hunting covers a defined scope and period; it may find no evidence, but cannot prove the absolute absence of compromise.

WHEN IT HELPS
A focused response
to a defined need.
Weak but persistent suspicion, exposure to a sector threat, newly available telemetry or a desire to test SOC visibility into selected behaviours.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Hypotheses
- sources and time window
- searches
- enrichment
- validation
- incident coordination if evidence is found
- recommendations
- conversion of useful hunts into detections
Deliverables
- Hunt plan
- investigation log
- validated results
- data limitations
- relevant indicators
- recommendations
- proposed new detections
Acceptance evidence
Hypotheses are addressed traceably; conclusions link to evidence; data gaps are explicit; anomalies follow the agreed escalation process; improvements are assigned.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
Which hypothesis is being examined? How much historical data exists? Who can authorise further investigation if suspicious evidence appears?
IMPORTANT BOUNDARIES
Without sufficient telemetry or history, some hypotheses remain unverifiable. Hunting is neither continuous monitoring nor a complete system audit.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company is concerned after a partner alert. Project: search available logs for relevant behaviours and access. Target outcome: an evidence-based finding for the reviewed period without claiming that no intrusion ever occurred.
Scenario 02
A SOC suspects abnormal service-account use. Project: compare activity, destinations and timing with owners. Target outcome: legitimate practices separated from anomalies; suspicious cases trigger a separate investigation.
Technology and reference context
References: MITRE ATT&CK and authorised SIEM/EDR/identity data; tools selected according to the hypothesis and available evidence.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
