Skip to content
Technology agents
Enterprise OperationsTechnologyCybersecurity / SOC

Threat Hunting Agent

Proactively hunts for adversary activity below the alerting threshold.

Forms hypotheses from fresh threat intel ('if this APT is in our sector, here is what their lateral movement looks like') and hunts for the predicted footprint across the telemetry. It sustains the search across data domains, parking and resuming leads. Confirmed leads become new detections; everything else becomes a documented hunt.

Authority

Act within policy

Team role

Coordinates the work

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Cybersecurity / SOC

Desk workflow

Detection, then triage, then investigation, then containment, then threat hunt and remediation, with evidence and ownership carried from the initial alert through resolution.

Collaboration

Coordinates specialist contributions

Decision boundary

Acts only within an explicit policy, permission and escalation boundary.

Systems and capabilities involved

  • Data lake / log search

    cross-domain pivots

  • Threat-intel platform

  • Detection-rule repository

    promote findings to detections

  • SOC triage agent

Handoffs

What this role gives and receives

Capabilities offered

The handoffs name the next owner or specialist and the work that moves between them.

Context

What the role needs to do the work

Current work
The hunt hypothesis and the evidence board.
Prior interactions
Prior hunts and which hypotheses paid off.
Policies and reference
Adversary TTP library, the bank's environment baseline.
Working method
Not specified for this role.

Checks and boundaries

What must be tested or reviewed

  1. 01New detection rules ship to shadow-mode first; false-positive rate gated before promotion.
  2. 02Citation discipline: every hunt finding links to the source telemetry.
  3. 03Containment actions route through the Guardrails agent for scope enforcement before commit.

Human authority

Acts only within an explicit policy, permission and escalation boundary.

Keep exploring