Lazo Lab Sign up

Defensive Security (Blue Team) / Detection

Lesson 24 of 32

Threat hunting

Threat hunting means searching for attackers who slipped past your alerts. Hunters start with a hypothesis, like 'someone is using stolen credentials', and dig through logs to check.

Key points

  • Start with a hypothesis
  • Search logs and endpoints
  • Turn findings into new detections
Watch a video on thisOpens YouTube search results for “Threat hunting” in a new tab

Quiz · +10 XP

What does a threat hunt start with?

Log in to save progress and earn XP.