Operations and defence (CyberOps)
Threat Hunting
Proactive hunting for adversaries that have already evaded automated defences.
What it involves
What we do
We start from hypotheses based on intelligence and your organisation's profile to search for indicators of compromise and attack techniques that the tools have not detected.
Operating flow: telemetry sources, correlation platform, analysts and coordinated response.
What's included
- Hunting campaigns based on hypotheses and MITRE ATT&CK
- Analysis of endpoint, network, identity and cloud telemetry
- Search for persistence, lateral movement and exfiltration
- One-off compromise assessment
- Conversion of findings into new detections
- Results report and recommendations
Who it's for
- Organisations with critical operations
- Entities that suspect a compromise
- SOC teams that want to raise their maturity
Deliverables
- Hunting campaign report
- New detection rules
- Remediation plan
Reference frameworks and standards
Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.
How we approach it
- DiscoverWe get to know your business, environment, risks and priorities.
- AnalyseWe assess maturity, exposure, compliance and real capabilities.
- DesignWe define strategy, roadmap, architecture and action plan.
- ImplementWe deliver controls, processes, technology and evidence.
- OperateWe monitor, respond and support continuous improvement.
- OptimiseWe measure results, reduce risk and evolve capabilities.
Related services
More in Operations and defence (CyberOps)
SOC
Security operations centre for continuous monitoring, detection and response.
Detect and respond- SOC service with SLA
- Response playbooks
- Monthly security report
SIEM Monitoring
Real-time collection, correlation and analysis of logs from across the entire infrastructure.
Detect and respond- Operational SIEM platform
- Use case catalogue
- Dashboards
MDR
Managed detection and response: experts who act on the threat rather than just reporting it.
Detect and respond- MDR service with response SLA
- Incident report
- Improvement recommendations
EDR / XDR and endpoint protection
Advanced protection for workstations, servers and mobile devices with detection and response at the endpoint.
Detect and respond- Deployed platform and policies
- Coverage and status report
- Response procedures
Incident response
Containment, eradication and recovery from incidents, on retainer or on demand.
Detect and respond- Incident response plan
- Playbooks by incident type
- Forensic and post-incident report
Cloud Security
Security for cloud and hybrid environments: configuration, identities, workloads and data.
Detect and respond- Cloud posture report
- Hardening plan
- Reference architecture
Let's talk
Does Threat Hunting fit your situation?
Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.

