Threat Intelligence

Why threat hunting should be about finding gaps, not ghosts

If something were amiss in your environment right now, would you know? Threat hunting doesn't need an intelligence team. Start with your own blind spots, one person and one hypothesis at a time.

Natasha Scott 5 min read
Why threat hunting should be about finding gaps, not ghosts

The UK National Risk Register 2026, published by the Cabinet Office in July, added several new cyber-related risks. They include digital resilience failure, cyber attacks on and disruption of data infrastructure, cyber attacks on water infrastructure, and cyber attacks on police systems. Digital resilience failure is among the risks now assessed as most likely.

None of this is new to anyone who follows incident reporting. Nearly every physical threat scenario now has a cyber counterpart, and the growing concerns - supplier concentration, loss of critical suppliers, and digital resilience - are the ones that many organisations have the least direct control over.

The question is what boards and security teams should do with this information. Debating the probability of a nation-state attack on your organisation produced no useful outcome, partly because you will never have enough information to settle the argument. The question that supports planning, preparedness and prioritisation is a different one - if it were happening now, would we see it?

That question leads us into the realm of threat hunting.

Why most organisations never start

If you mention "threat hunting" to a mid-sized organisation most people picture a specialist team tracking a named adversary through the network, fed by a paid intelligence service. That assumption is exactly why so many decide hunting is not for them.

Hunting the adversary – or ghosts – presents real problems for a lean team. You are chasing an actor you are unlikely ever to meet. It needs threat intelligence, budget and headcount. Indicators of compromise expire, which means that the work is never finished.

However, hunting your own gaps is a different exercise. Attacker behaviours are finite, durable and mostly visible. The work uses the logs and people you already have. You are examining your own estate rather than a threat feed, which means that any organisation can do it.

The shift that makes this possible is the move from detecting indicators to detecting behaviours. An IP address or file hash is useful for a few days. The way an attacker escalates privileges, moves laterally or stages data changes far more slowly – and it is evident in your own telemetry, regardless of who the attacker is, and if you know where to look.

Choosing what to hunt

The hardest question for a team without an intelligence function is where to start. The answer is with your own environment and from what you would most hate to lose, not from a threat feed.

A good first place to look is the difference between two lists that are often treated as the same thing.

  • Asset management records what you own. It is built from procurement, the CMDB and finance records, and reflects what the organisation believes it has. Usually, it is updated on a change cycle. It says nothing about anything nobody registered.
  • Attack surface management shows what is exposed. It is built from what is reachable and resolvable from outside, and includes the forgotten, the inherited and shadow IT. It can change daily without anyone raising a ticket. Overlay vulnerability data and you have what an attacker is working from.

AI agents - the new population

AI agents are a timely example of choosing what to hunt. Agents act with credentials, at machine speed, across systems that were scoped for human users - and most organisations cannot yet say how many are running or who owns them.

That creates a detection problem. An agent following its own instructions and an agent following an attacker's instructions produce the same kind of activity, from an authorised account. Only the behaviour allows you to tell them apart. At the same time, frontier models widen what an attacker can attempt and how quickly.

The defensive answer is not new. It is being able to see your own estate. Nobody hunts for what they can’t see, so the objective of the first hunt may simply be to uncover what agents are operating, under whose credentials, and what they are touching.

Running the hunt

A hunting programme does not need a new team or a new product. It needs three things:

1. A detection engineer - one person who already knows the estate.
2. One day a week - protected, repeating time. A hunt that only happens when things are quiet never happens.
3. One hypothesis - a specific attacker behaviour, in a named part of the estate, that you could plausibly see.

Repeat that, and you have a threat hunting programme.

Finding nothing is still a result – if you can prove it

Most hunts find nothing. That is normal, and it is still a useful outcome, but only if you can show that you would have seen the behaviour had it been there.

"We found nothing" and "we cannot see that part of the estate" produce the same result. But they mean very different things, and only one of them should reassure a board.

Every hunt should produce two outputs - what you looked for, and the evidence that your logging, retention and coverage would have recorded it. Where that evidence doesn't exist, the hunt has done its job - it has found a blind spot, and you now know exactly what to fix.

Resilience still depends on knowing your gaps

Much of the current national guidance points towards building resilience. Which means assuming that you will be compromised, planning the recovery and rehearsing the scenarios. As sound as that advice is, recovery plans are written for the failures you have imagined. Hunting is how you find the ones you haven't.

AI makes this even more critical. Attackers can attempt more, faster and at lower cost, which compresses the time between a gap appearing and someone exploiting it. Resilience is the goal, and it still depends on knowing where your gaps are.

Five takeaways

1. Don't debate how likely an attack is, ask whether you would be able to see it.
2. Hunt gaps, not ghosts - your own blind spots, not an imagined adversary.
3. Start from what you would most hate to lose, not from a threat feed.
4. Begin with one person, on one day, testing one hypothesis, then repeat. That is a threat hunting programme.
5. We found nothing" only counts if you could have seen it.

Further reading

NCSC — Cyber Assessment Framework, principle C2
NCSC – observability and threat hunting
UK Government – Detecting the Unknown

 

Share this article
Get in touch

Ready to strengthen your cyber resilience?

Talk to one of our specialists about how Talanos can support your team.

Book a consultation →