A SOC team wants to implement threat hunting to proactively find attackers who evaded existing detection. What best describes the threat hunting methodology?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because threat hunting is a proactive, human-led process where analysts form hypotheses based on threat intelligence and attack patterns, then investigate data to find evidence of attacker activity that bypassed automated detection. A is wrong because running SIEM rules more frequently only improves detection speed for known patterns; it does not find unknown threats.
Full explanation below image
Full Explanation
B is correct because threat hunting is a proactive, human-led process where analysts form hypotheses based on threat intelligence and attack patterns, then investigate data to find evidence of attacker activity that bypassed automated detection. A is wrong because running SIEM rules more frequently only improves detection speed for known patterns; it does not find unknown threats. C is wrong because adding IOCs to blocklists is reactive threat intelligence consumption, not proactive threat hunting. D is wrong because vulnerability scanning identifies weaknesses, not attacker activity that is already present.