Threat Hunting Agent
Proactively hunts for adversary activity below the alerting threshold.
Forms hypotheses from fresh threat intel ('if this APT is in our sector, here is what their lateral movement looks like') and hunts for the predicted footprint across the telemetry. It sustains the search across data domains, parking and resuming leads. Confirmed leads become new detections; everything else becomes a documented hunt.
Authority
Act within policy
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Cybersecurity / SOC
Desk workflow
Detection, then triage, then investigation, then containment, then threat hunt and remediation, with evidence and ownership carried from the initial alert through resolution.
Collaboration
Coordinates specialist contributions
Decision boundary
Acts only within an explicit policy, permission and escalation boundary.
Systems and capabilities involved
Data lake / log search
cross-domain pivots
Threat-intel platform
Detection-rule repository
promote findings to detections
SOC triage agent
Handoffs
What this role gives and receives
Capabilities offered
The handoffs name the next owner or specialist and the work that moves between them.
Handoff to
Receives from
Context
What the role needs to do the work
- Current work
- The hunt hypothesis and the evidence board.
- Prior interactions
- Prior hunts and which hypotheses paid off.
- Policies and reference
- Adversary TTP library, the bank's environment baseline.
- Working method
- Not specified for this role.
Checks and boundaries
What must be tested or reviewed
- 01New detection rules ship to shadow-mode first; false-positive rate gated before promotion.
- 02Citation discipline: every hunt finding links to the source telemetry.
- 03Containment actions route through the Guardrails agent for scope enforcement before commit.
Human authority
Acts only within an explicit policy, permission and escalation boundary.
Keep exploring