Skip to main content

Live panel · Oct 8Who's Accountable at Machine Speed? Free, with the recording either way.

Save my seat
Proactive threat hunting
ThreatHunt™

The threats that matter most never trigger an alert.

Alert-only monitoring waits for something to trip. Our Tier-3 analysts go looking before it does, across your clients' endpoint, identity, cloud, and network telemetry, mapped to MITRE ATT&CK.

Delivered through your practice, never around it.

Share
Client telemetryAll clear
Caught: native-tool execution · T1204.002 · no alert fired
The alarm cannot see everything

An alarm knows when a door is forced. It says nothing when someone is invited in.

A convincing verification page. A command pasted by the user and run through native Windows tooling. No signature to match, no alert to fire. That is the ground a hunt covers. We categorize every finding by technique, never by a transient campaign name, so a report holds its meaning long after a threat's nickname has changed.

Social-engineering-driven executionT1204Fake update and paste-and-run luresT1059Identity abuse and evasionT1556
What it is

Hypothesis-driven. Human-led. Tier-3.

Every hunt starts from a hypothesis about how an adversary would operate undetected inside an environment. Analysts pursue it by hand through raw telemetry, validate every lead, and discard the noise. This is not automated triage. It is forensic work, and it surfaces the quiet footholds that never generate an alert: native-tool execution, dormant persistence, and identity abuse that standard platforms stay silent on.

ThreatHunt™ sits on top of the SOC coverage your clients already have. It does not replace monitoring, it goes looking where monitoring has nothing to report.

Cross-source correlation8/8 linked
8 telemetry domains
  • EDR
  • ITDR
  • Network
  • Cloud
  • AI-DR
  • SaaS
  • Devices
  • Data
Telemetry in scope
EDR

Process, script, and execution telemetry

ITDR

Sign-in, privilege, and token abuse

Network

Egress, beaconing, and lateral movement

Cloud

Control-plane changes and workload activity

AI-DR

Model, agent, and prompt-surface activity

SaaS

App sessions, sharing, and OAuth grants

Devices

Unmanaged, OT, and IoT presence

Data

Access, staging, and exfiltration paths

What you get

Three things land on your desk, every cycle.

01

Hypothesis-driven hunts

Every cycle targets a specific advanced evasion tactic across your enrolled clients. Analysts pursue the hypothesis by hand, validate every lead, and discard the noise.

02

Signal, not noise

No raw log dumps. Findings arrive with severity, the exact process chain, the host, and the user, each mapped to its MITRE ATT&CK technique.

03

A white-label hunt report

Written for a non-technical business owner, with remediation your helpdesk can action directly. Your logo on the cover, presented as your own.

Why it matters for your MSP

When nothing happens, this is your proof.

The hardest question in the channel is the quiet one: what am I paying you for? A white-labeled hunt report answers it with documented, board-ready evidence that someone is actively hunting on your clients' behalf. It justifies the retainer, and it wins the QBR.

Any provider can say they hunt. ThreatHunt™ lets you prove it, in writing, with your name on the cover.

Complimentary first hunt

See it on your own ground.

We will run one hunt on a client of your choosing, at no cost to you or them, and hand you the report. Same SOC that protects your paying clients, every hunt.

Engagement model
  • Never around you. Delivered through you, under your brand.
  • Monthly sprints. Each cycle targets a specific advanced evasion tactic.
  • Your brand. The report carries your logo, not ours.
  • No raw log dumps. Signal only, with context and next steps.

Built for partners serving regulated industries, healthcare, finance, and DoD or CMMC environments, and any practice ready to move a client from reactive to proactive.

ThreatHunt™ · managed threat hunting

Pick a cadence. Start with a hunt on us.

Three cadences, one methodology, one report. Choose the rhythm that fits, leave a work email, and a Vijilan hunter confirms the data sources in reach and a start date within one business day.

  • Runs on the CrowdStrike Falcon subscription the environment already has
  • Same methodology and the same case report at every cadence
  • White-label when delivered through a partner
Requesting ThreatHunt Standard · white-label, for your clients
Work email required · no card, no contract on this page
A hunter replies within one business day.
The methodology

Four ways to hunt. Most engagements blend them.

A CVE disclosure starts as an indicator search, gets investigated through the technique it exploits, and every query is framed as a testable hypothesis. The data sources in scope are confirmed at the start of each engagement — never assumed.

It complements Falcon Adversary OverWatch and Falcon Complete rather than replacing them: those services cover the endpoint, and ThreatHunt™ carries the same standard of proactive investigation across identity, network, cloud control planes and SaaS.

Anomaly-based

Continuous review of endpoint, network and identity telemetry for deviations from normal behavior that automated detections did not flag.

IOC-based

Targeted search for indicators — domains, IPs, hashes, file names — tied to newly disclosed campaigns, threat advisories and intelligence reports.

TTP-based

Investigation mapped to specific MITRE ATT&CK techniques, looking for the behavior pattern rather than a single known-bad indicator.

Hypothesis-driven

A hunt built around a specific, documented hypothesis — "if a paste-and-run lure reached this environment, explorer.exe would be spawning PowerShell" — validated or refined against real telemetry.

How far back it reaches

Scheduled hunts: 30–90 days. Disclosure hunts: as far back as the campaign goes.

Scheduled TTP and anomaly hunts run over a rolling 30–90 day telemetry window. When a hunt is triggered by a CVE or a published campaign, the lookback extends to the earliest confirmed exploitation date the disclosing researcher documented — not a fixed number of days. If the campaign has been active for five months, the hunt looks back five months.

It runs on the CrowdStrike Falcon subscription you already have — Falcon LogScale, Falcon Insight XDR, Falcon Adversary Intelligence — with Vijilan’s Cribl pipeline normalizing whatever else the environment produces. No new tools to buy. Environments without full sensor telemetry are hunted through Windows Security Events, firewall logs and Microsoft 365 audit instead.

Inside the report
  • Hypothesis & TTPs. The tactic, technique and MITRE ATT&CK IDs under investigation, the data sources used, and the detection opportunities they imply.
  • Every query, every result. Each query run and its plain-English finding — confirmed finding, confirmed false positive, or pending your confirmation. Negative results are documented as valid findings, never omitted.
  • IOCs & evidence. Any indicators relevant to the hunt, with query outputs retained in the case file.
  • A new detection use case. When a hunt surfaces a pattern worth watching, it becomes an automated detection — so the next occurrence is caught without waiting for the next hunt.
  • Recommendations. Plain-English next steps and a summary disposition, written so a non-technical owner can act on them.
Engagement cadence

Quarterly

One hypothesis- or TTP-driven hunt per quarter, 30-day lookback, focused on a single technique or campaign.

Monthly

One scheduled hunt per month rotating through the technique library, with a 30–90 day rolling lookback.

Continuous

Everything in Monthly, plus ad hoc hunts kicked off within 24–48 hours of a major public disclosure, at priority turnaround.

Same methodology and the same report at every cadence — the difference is frequency and how fast a disclosure-driven hunt kicks off. Delivered engagements to date span SOC-initiated hunts on paste-and-run lures, command-shell and volume-shadow abuse, and scripting-interpreter abuse, plus client-requested CVE retrospectives.

Hunting Beyond the Endpoint

The ThreatHunt™ whitepaper: the detection gap, the four hunting methodologies, why hunting has to reach identity, network, cloud and SaaS, what a decision-grade report contains, and six questions to ask any provider who says they hunt. Work email required.

We use your email to send Vijilan resources. No spam, unsubscribe anytime.

Common questions

How far back does a threat hunt look?

Two standards. Scheduled hunts run over a rolling 30–90 day telemetry window. Disclosure-driven retrospective hunts reach back to the earliest confirmed exploitation date of that specific campaign, as published by the disclosing researcher — not a fixed number of days.

Do we need to buy any new tools for ThreatHunt?

No. ThreatHunt runs on the CrowdStrike Falcon subscription you already have — Falcon LogScale, Falcon Insight XDR and Falcon Adversary Intelligence — plus Vijilan’s own Cribl-based normalization pipeline. There is no third-party tool purchase and no additional license cost baked into delivery.

What if our environment doesn’t have full Falcon sensor telemetry?

The data sources in scope are confirmed at the start of every engagement, not assumed. Environments without raw sensor telemetry are hunted through secondary sources — Windows Security Events, firewall logs, Microsoft 365 audit — normalized through the Cribl pipeline.

What does a ThreatHunt engagement deliver?

One document: a Threat Hunt Case Report in a standardized template — hypothesis and MITRE ATT&CK techniques, every query run with its result (negative results documented as valid findings), IOCs, evidence, any new detection use case created from the findings, and plain-English recommendations. White-label, presented as your own.

Pass it on

Know a provider still waiting on the alarm?

Send them this page. It explains what a hunt covers, what lands on their desk, and why the quiet months are the ones worth proving.

We protect the protectors.SOC 2 Type II and ISO 27001 certified · CrowdStrike Powered Service Provider
Start outside

Before we hunt inside, see what an attacker sees.

ThreatAssess™ maps your external attack surface the way an adversary would: exposed services, forgotten subdomains, credentials already circulating. No agent to install, no call to book. It is the honest first look, and it costs nothing.

Free · no credit card

Start your free assessment

All we need is a domain. No agent to install.

// work email required · no credit card · results within two business days

Hypothesis family

AI agents

Agent processes spawning shells or touching credential stores, persistence installed by an agent, and MCP tool descriptions that don’t match what the tool does. Hunted as part of AgentDefend.

See AgentDefend