A municipal SOC notices stealthy persistence may exist even when no high-severity alert fired. Which approach best describes threat hunting in this context?
Select an answer to reveal the explanation.
Short Explanation
Threat hunting is walking the beat looking for odd footprints even when the alarm never rang. Municipal analysts dig through telemetry for persistence tricks that quiet alerts miss. Sitting only on SIEM tickets is pure reaction, not hunting.
Full Explanation
Threat hunting is a proactive search for indicators and behaviors that may evade existing detections, complementing alert-driven incident response. It uses hypothesis-driven analysis of endpoint, identity, and network telemetry. Relying only on tickets, dropping continuous logging for periodic scans, or disabling EDR reduces visibility and is not hunting.