The threats that matter most never trigger an alert.
Alert-only monitoring waits for something to trip. Our Tier-3 analysts go looking before it does, across your clients' endpoint, identity, cloud, and network telemetry, mapped to MITRE ATT&CK.
Delivered through your practice, never around it.
An alarm knows when a door is forced. It says nothing when someone is invited in.
A convincing verification page. A command pasted by the user and run through native Windows tooling. No signature to match, no alert to fire. That is the ground a hunt covers. We categorize every finding by technique, never by a transient campaign name, so a report holds its meaning long after a threat's nickname has changed.
Hypothesis-driven. Human-led. Tier-3.
Every hunt starts from a hypothesis about how an adversary would operate undetected inside an environment. Analysts pursue it by hand through raw telemetry, validate every lead, and discard the noise. This is not automated triage. It is forensic work, and it surfaces the quiet footholds that never generate an alert: native-tool execution, dormant persistence, and identity abuse that standard platforms stay silent on.
ThreatHunt™ sits on top of the SOC coverage your clients already have. It does not replace monitoring, it goes looking where monitoring has nothing to report.
- EDR
- ITDR
- Network
- Cloud
- AI-DR
- SaaS
- Devices
- Data
Process, script, and execution telemetry
Sign-in, privilege, and token abuse
Egress, beaconing, and lateral movement
Control-plane changes and workload activity
Model, agent, and prompt-surface activity
App sessions, sharing, and OAuth grants
Unmanaged, OT, and IoT presence
Access, staging, and exfiltration paths
Three things land on your desk, every cycle.
Hypothesis-driven hunts
Every cycle targets a specific advanced evasion tactic across your enrolled clients. Analysts pursue the hypothesis by hand, validate every lead, and discard the noise.
Signal, not noise
No raw log dumps. Findings arrive with severity, the exact process chain, the host, and the user, each mapped to its MITRE ATT&CK technique.
A white-label hunt report
Written for a non-technical business owner, with remediation your helpdesk can action directly. Your logo on the cover, presented as your own.
When nothing happens, this is your proof.
The hardest question in the channel is the quiet one: what am I paying you for? A white-labeled hunt report answers it with documented, board-ready evidence that someone is actively hunting on your clients' behalf. It justifies the retainer, and it wins the QBR.
Any provider can say they hunt. ThreatHunt™ lets you prove it, in writing, with your name on the cover.
See it on your own ground.
We will run one hunt on a client of your choosing, at no cost to you or them, and hand you the report. Same SOC that protects your paying clients, every hunt.
- Never around you. Delivered through you, under your brand.
- Monthly sprints. Each cycle targets a specific advanced evasion tactic.
- Your brand. The report carries your logo, not ours.
- No raw log dumps. Signal only, with context and next steps.
Built for partners serving regulated industries, healthcare, finance, and DoD or CMMC environments, and any practice ready to move a client from reactive to proactive.
Pick a cadence. Start with a hunt on us.
Three cadences, one methodology, one report. Choose the rhythm that fits, leave a work email, and a Vijilan hunter confirms the data sources in reach and a start date within one business day.
- Runs on the CrowdStrike Falcon subscription the environment already has
- Same methodology and the same case report at every cadence
- White-label when delivered through a partner
Four ways to hunt. Most engagements blend them.
A CVE disclosure starts as an indicator search, gets investigated through the technique it exploits, and every query is framed as a testable hypothesis. The data sources in scope are confirmed at the start of each engagement — never assumed.
It complements Falcon Adversary OverWatch and Falcon Complete rather than replacing them: those services cover the endpoint, and ThreatHunt™ carries the same standard of proactive investigation across identity, network, cloud control planes and SaaS.
Anomaly-based
Continuous review of endpoint, network and identity telemetry for deviations from normal behavior that automated detections did not flag.
IOC-based
Targeted search for indicators — domains, IPs, hashes, file names — tied to newly disclosed campaigns, threat advisories and intelligence reports.
TTP-based
Investigation mapped to specific MITRE ATT&CK techniques, looking for the behavior pattern rather than a single known-bad indicator.
Hypothesis-driven
A hunt built around a specific, documented hypothesis — "if a paste-and-run lure reached this environment, explorer.exe would be spawning PowerShell" — validated or refined against real telemetry.
Scheduled hunts: 30–90 days. Disclosure hunts: as far back as the campaign goes.
Scheduled TTP and anomaly hunts run over a rolling 30–90 day telemetry window. When a hunt is triggered by a CVE or a published campaign, the lookback extends to the earliest confirmed exploitation date the disclosing researcher documented — not a fixed number of days. If the campaign has been active for five months, the hunt looks back five months.
It runs on the CrowdStrike Falcon subscription you already have — Falcon LogScale, Falcon Insight XDR, Falcon Adversary Intelligence — with Vijilan’s Cribl pipeline normalizing whatever else the environment produces. No new tools to buy. Environments without full sensor telemetry are hunted through Windows Security Events, firewall logs and Microsoft 365 audit instead.
- Hypothesis & TTPs. The tactic, technique and MITRE ATT&CK IDs under investigation, the data sources used, and the detection opportunities they imply.
- Every query, every result. Each query run and its plain-English finding — confirmed finding, confirmed false positive, or pending your confirmation. Negative results are documented as valid findings, never omitted.
- IOCs & evidence. Any indicators relevant to the hunt, with query outputs retained in the case file.
- A new detection use case. When a hunt surfaces a pattern worth watching, it becomes an automated detection — so the next occurrence is caught without waiting for the next hunt.
- Recommendations. Plain-English next steps and a summary disposition, written so a non-technical owner can act on them.
Quarterly
One hypothesis- or TTP-driven hunt per quarter, 30-day lookback, focused on a single technique or campaign.
Monthly
One scheduled hunt per month rotating through the technique library, with a 30–90 day rolling lookback.
Continuous
Everything in Monthly, plus ad hoc hunts kicked off within 24–48 hours of a major public disclosure, at priority turnaround.
Same methodology and the same report at every cadence — the difference is frequency and how fast a disclosure-driven hunt kicks off. Delivered engagements to date span SOC-initiated hunts on paste-and-run lures, command-shell and volume-shadow abuse, and scripting-interpreter abuse, plus client-requested CVE retrospectives.
Hunting Beyond the Endpoint
The ThreatHunt™ whitepaper: the detection gap, the four hunting methodologies, why hunting has to reach identity, network, cloud and SaaS, what a decision-grade report contains, and six questions to ask any provider who says they hunt. Work email required.
How far back does a threat hunt look?
Two standards. Scheduled hunts run over a rolling 30–90 day telemetry window. Disclosure-driven retrospective hunts reach back to the earliest confirmed exploitation date of that specific campaign, as published by the disclosing researcher — not a fixed number of days.
Do we need to buy any new tools for ThreatHunt?
No. ThreatHunt runs on the CrowdStrike Falcon subscription you already have — Falcon LogScale, Falcon Insight XDR and Falcon Adversary Intelligence — plus Vijilan’s own Cribl-based normalization pipeline. There is no third-party tool purchase and no additional license cost baked into delivery.
What if our environment doesn’t have full Falcon sensor telemetry?
The data sources in scope are confirmed at the start of every engagement, not assumed. Environments without raw sensor telemetry are hunted through secondary sources — Windows Security Events, firewall logs, Microsoft 365 audit — normalized through the Cribl pipeline.
What does a ThreatHunt engagement deliver?
One document: a Threat Hunt Case Report in a standardized template — hypothesis and MITRE ATT&CK techniques, every query run with its result (negative results documented as valid findings), IOCs, evidence, any new detection use case created from the findings, and plain-English recommendations. White-label, presented as your own.
Before we hunt inside, see what an attacker sees.
ThreatAssess™ maps your external attack surface the way an adversary would: exposed services, forgotten subdomains, credentials already circulating. No agent to install, no call to book. It is the honest first look, and it costs nothing.
Hypothesis family
AI agents
Agent processes spawning shells or touching credential stores, persistence installed by an agent, and MCP tool descriptions that don’t match what the tool does. Hunted as part of AgentDefend.
See AgentDefend