Skip to content

Home Expertise / Security operations

SOC / SOC-06

Proactive compromise investigation — threat hunting

Search for suspicious behaviour using explicit hypotheses beyond existing alerts. Hunting covers a defined scope and period; it may find no evidence, but cannot prove the absolute absence of compromise.

WHEN IT HELPS

A focused response
to a defined need.

Weak but persistent suspicion, exposure to a sector threat, newly available telemetry or a desire to test SOC visibility into selected behaviours.

AT A GLANCE

Family
Security operations

Engagement
Service or implementation

Reference
SOC-06

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Hypotheses
  • sources and time window
  • searches
  • enrichment
  • validation
  • incident coordination if evidence is found
  • recommendations
  • conversion of useful hunts into detections

Deliverables

  • Hunt plan
  • investigation log
  • validated results
  • data limitations
  • relevant indicators
  • recommendations
  • proposed new detections

Acceptance evidence

Hypotheses are addressed traceably; conclusions link to evidence; data gaps are explicit; anomalies follow the agreed escalation process; improvements are assigned.

DELIVERY

How the work is structured.

Approach

Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.

Prerequisites & responsibilities

Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.

Scope factors

Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.

Questions to clarify

Which hypothesis is being examined? How much historical data exists? Who can authorise further investigation if suspicious evidence appears?

IMPORTANT BOUNDARIES

Without sufficient telemetry or history, some hypotheses remain unverifiable. Hunting is neither continuous monitoring nor a complete system audit.

Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company is concerned after a partner alert. Project: search available logs for relevant behaviours and access. Target outcome: an evidence-based finding for the reviewed period without claiming that no intrusion ever occurred.

Scenario 02

A SOC suspects abnormal service-account use. Project: compare activity, destinations and timing with owners. Target outcome: legitimate practices separated from anomalies; suspicious cases trigger a separate investigation.

Technology and reference context

References: MITRE ATT&CK and authorised SIEM/EDR/identity data; tools selected according to the hypothesis and available evidence.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.