Proactive Threat Hunting with MITRE ATT&CK
Threat hunting starts from an uncomfortable assumption: the adversary is already inside, and your alerts have not fired. Rather than waiting for a tool to notice, the hunter forms a hypothesis about how an intruder would operate and goes looking for the evidence — turning every confirmed hunch into a detection that never needs hunting again.
Detection and response are reactive by design — they wait for a known-bad signal. Threat hunting is the proactive complement: a human-led, hypothesis-driven search through your telemetry for adversary behaviour that automated controls missed. It exists because sophisticated intrusions are built to look normal, and dwell times are measured in weeks. Done well, hunting does more than find intruders; it systematically converts what analysts learn into new detections, so the same technique cannot hide twice. This article covers the method, the theory that makes it efficient, and how MITRE ATT&CK gives your hunts structure.
Starting from a hypothesis
The defining feature of a hunt is that it begins with a testable idea, not a tool. A good hypothesis is specific enough to search for and grounded in how real adversaries behave: "an attacker who compromised a workstation would use a built-in scripting host to run encoded commands, so let me look for that pattern across our endpoints." Hypotheses come from threat intelligence about active campaigns, from ATT&CK techniques relevant to your environment, from anomalies noticed in passing, and from the crown-jewel systems you most need to protect.
The pyramid of pain
Not all indicators are equally valuable to hunt for, and David Bianco's pyramid of pain explains why. At the bottom sit hash values, IP addresses, and domain names — trivial for an attacker to change, so detections built on them are brittle and expire quickly. As you climb, you reach network and host artefacts, then tools, and at the apex TTPs — the tactics, techniques, and procedures that describe how an adversary operates. Detecting at the TTP level causes the attacker the most pain, because changing their fundamental methods is expensive and slow. Effective hunts aim high on the pyramid.
Why the top matters
An adversary can rotate a malicious domain in seconds, but redesigning how they escalate privileges or move laterally may cost weeks of retooling. When your hunts and the detections they produce target behaviour rather than indicators, you force that expensive change — and you catch not just today's campaign but the next one that reuses the same technique.
Hunt at the top of the pyramid. A detection tied to an IP address dies with that IP; a detection tied to a technique keeps working long after the attacker changes their infrastructure.
Structuring hunts with ATT&CK
MITRE ATT&CK is the map that keeps hunting from being ad hoc. Its matrix of tactics — the adversary's goals, from initial access through execution, persistence, credential access, lateral movement, and exfiltration — and the concrete techniques under each gives you a systematic backlog to work through. You can prioritise the techniques most relevant to your industry's threat actors, confirm you have the data sources needed to see each one, and honestly rate your coverage. ATT&CK turns "are we secure?" into a gridded, answerable set of specific hunts.
Collect, analyze, and pivot
With a hypothesis chosen, the hunter gathers the relevant telemetry — endpoint process events, authentication logs, network flows, DNS — and searches it. The core analytic skill is baselining: understanding what normal looks like so the abnormal stands out. A service account logging in interactively at 3 a.m., a rare parent-child process relationship, or an internal host suddenly beaconing to a new destination are the kinds of outliers a hunter learns to pivot on, following one anomaly to the next until a picture forms or the hypothesis is cleanly ruled out.
From finding to detection
A hunt that ends with "we looked and found nothing suspicious" is still a success — but its lasting value is the detection it leaves behind. Whether or not the hunt uncovered an intruder, the analytic that was developed to test the hypothesis should be documented and, where it is precise enough, promoted into an automated detection rule. This is how a hunting program compounds: each cycle permanently expands what your automation catches, so human effort is spent on genuinely new questions rather than re-checking old ones. Document the hypothesis, the data used, the outcome, and the detection produced, then feed that learning into the next hypothesis and go around the loop again.
Key takeaways
- Hunting is proactive and hypothesis-driven — it assumes a breach and searches for what alerts missed.
- Aim high on the pyramid of pain: detections tied to TTPs outlast those tied to IPs and hashes.
- MITRE ATT&CK turns hunting into a systematic backlog and an honest coverage map.
- Baselining normal behaviour is the core skill that lets true anomalies surface.
- Every hunt should end by documenting a detection — that is how the program compounds over time.