Hunting vs Alert Triage
What is it?
Alert triage is reactive: a detection fires and an analyst responds to it. Threat hunting is proactive: no alert has fired, and the hunter deliberately searches telemetry for attacker behavior on the assumption that some intrusions evade detection.
Why it matters
If you only respond to alerts, you only ever find what your detections already catch — hunting is how an organization finds the attacker its tools missed.
Where you see it
The difference between the SOC queue (reactive) and a scheduled hunt (proactive) at Qasr Retail.
What normal looks like
Hunts that start from a hypothesis and end with a documented conclusion — supported or not.
What suspicious looks like
Not applicable directly — hunting is the activity, not a finding; the suspicious thing is what a hunt looks for.
How analysts investigate
By assuming compromise as a starting posture and asking 'if an attacker were here doing X, what would the telemetry show?' — then going to look.
Common beginner mistakes
- Waiting for something to look wrong before hunting — a hunt is planned, not triggered; if an alert triggered it, that is triage.
Qasr Retail's SOC closes 200 alerts a day. Its brand-new hunt team asks a different question entirely: 'what is happening on our network that never generated an alert at all?'
Quick check
A hunter opens the SIEM with no alert in hand and searches for a specific attacker behavior. Is this hunting or triage?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.