Terminology Index
Glossary
1801 terms
Showing 769-800 of 1801 terms
Hunt Hypothesis
A specific, testable statement of what malicious activity might be present and how it would show up in data, that drives a threat hunt, giving it a clear question to investigate rather than aimless searching.
Every structured hunt starts from a hypothesis: an educated, testable claim like 'an attacker is using a particular technique, which would appear as this evidence in that telemetry.' It focuses the hunt, defines what data and analysis are needed, and makes the result meaningful, the hypothesis is confirmed or refuted. Good hypotheses come from threat intelligence, knowledge of attacker behavior, and the environment, distinguishing hypothesis-driven hunting from random data trawling.
Introduced in: Threat Hunting Fundamentals
Examples
- Hypothesizing that an attacker is abusing a specific tool, visible in process logs.
- Framing a hunt around a technique an intel report described.
- Stating expected evidence so the hypothesis can be confirmed or refuted.
No related terms linked yet.
