Strategic Foresight, Threat Hunting Doctrine

    Your Threat Hunters Are Bringing Knives to a Drone War

    And they don't even know it yet. Why most SOCs are equipped for a threat landscape that no longer exists, and what an AI-era hunting doctrine actually looks like.

    April 18, 202612 min read
    Threat Hunting
    AI Adversaries
    SOC Modernisation
    Spharaka Sphere™
    Spharaka diagram: hypotheses generated continuously and tested across the whole telemetry set.

    Three months ago, a Fortune 500 company wired $47 million to an account it shouldn't have.

    No zero-day was involved. No nation-state. No insider gone rogue.

    The attacker was a large language model. It cost roughly $200 to operate.

    Over 48 hours, the model scraped the company's public GitHub repositories, parsed LinkedIn profiles, dissected quarterly earnings calls, and cross-referenced job postings to reverse-engineer internal approval workflows. It identified the financial controller by name, studied her writing cadence from social posts, mapped her reporting chain, and then generated 300 individually tailored spear-phishing emails, each one linguistically distinct, each one surgically targeted.

    One landed.

    From there, the model studied the compromised inbox, learned the company's invoice formatting conventions, identified an upcoming vendor payment cycle, and submitted a wire transfer request so flawless it sailed through two layers of human review.

    Seventy-two hours. Reconnaissance to exfiltration. The money vanished across six jurisdictions before anyone flagged the anomaly.

    Meanwhile, the company's threat hunting team was still writing queries to investigate a suspicious login from the previous week.

    This is not a thought experiment. This is the threat landscape as it exists today, and the overwhelming majority of security operations centres are not equipped to survive it.

    The Asymmetry Nobody Wants to Name

    There is a particular kind of institutional denial that takes hold when the rules of a game change faster than the players can adapt. You see it in militaries clinging to cavalry doctrine after the invention of the machine gun. You see it in newsrooms insisting print advertising will recover. And you see it, right now, in cybersecurity, an industry that has spent two decades building defences calibrated for human-speed adversaries and is only beginning to reckon with what happens when the adversary thinks in milliseconds.

    The math has shifted beneath everyone's feet.

    60 days

    Average dwell time in 2019. Embarrassing, but survivable. Defenders had a window.

    16 days

    Average dwell time by 2023, after attacker automation matured.

    < 24 hrs

    Full kill chain execution by dark LLMs in 2025. Reconnaissance to exfiltration at machine speed.

    Your threat hunters still compose queries by hand. That is not a gap. That is a species-level mismatch.

    Inside the Modern SOC: A Quiet Crisis

    Walk into any security operations centre in any major enterprise today. You will find talented, overworked analysts drowning in a flood they were never designed to manage.

    The numbers tell a story that no vendor slide deck wants to confront honestly. The average SOC analyst faces north of 1,000 alerts per day, with false positive rates hovering above 95 percent. Threat intelligence arrives as dense PDF reports that sit unread in shared drives. SIEM queries, the primary investigative instrument, take hours to write and minutes to crash. Coverage gaps exist everywhere, but no one can map them. Dwell time is still measured in weeks.

    And yet, by some unspoken collective agreement, everyone pretends the machinery is functioning. It isn't. The adversary just acquired artificial general reasoning as an offensive weapon. The defence is still running grep on log files. That disparity doesn't close on its own. It widens exponentially.

    Five Comfortable Fictions the Industry Refuses to Abandon

    Every discipline under existential pressure develops its own mythology, reassuring stories that delay the painful work of adaptation. Cybersecurity has at least five.

    Fiction One: Indicators of Compromise Will Save Us

    When malware rewrites its own signature every 30 seconds, a file hash blacklist is not a detection strategy. It is a historical exhibit. When phishing infrastructure spins up and burns down faster than any feed can catalogue, your IOC database is documenting the past, not illuminating the present.

    The uncomfortable conclusion: if your hunting programme is still anchored to indicators of compromise, you are systematically looking where the threat no longer is.

    Fiction Two: We Have Good Threat Intelligence

    Most organisations don't have threat intelligence. They have threat inventory: 47 feeds, in 12 formats, scattered across six platforms, with no correlation layer, no contextual enrichment, and no operational integration.

    Intelligence answers a single question: Is this happening in my environment, right now? If your threat intel cannot answer that in under 60 seconds, it is not intelligence. It is overhead.

    Fiction Three: Behavioural Detection Is Too Complex

    You know what is genuinely complex? Explaining to a board of directors why a threat actor lived inside your network for six weeks while your team manually correlated alerts across 15 security products.

    Behavioural detection is not inherently complex. The platforms most organisations use to attempt it are. On the right infrastructure, a behavioural hunt is as straightforward as: Show me Office processes that spawned PowerShell and accessed files outside their historical pattern. One sentence. No query language. No data science degree.

    Fiction Four: AI Is Just Hype

    Ransomware operators are using LLMs to craft personalised extortion communications referencing victims' org charts and regulatory exposure. Nation-state actors are generating polymorphic implants that rewrite themselves on every execution. Script kiddies with no formal training are automating multi-stage attack chains that would have required a skilled operator and weeks of effort 18 months ago. AI in adversaries' hands is a force multiplier already deployed in the field.

    Fiction Five: We Just Need Better Analysts

    No. You need to stop wasting the analysts you have.

    The typical threat hunter's time breaks down roughly as follows: 40 percent writing and tuning queries, 30 percent correlating data across siloed platforms, 20 percent triaging false positives, and 10 percent, one-tenth of their professional capacity, actually hunting threats. That is not a talent deficit. It is a tools failure of staggering proportion.

    Toward a Doctrine for the Age of AI Adversaries

    What does threat hunting look like when you stop optimising for a threat landscape that no longer exists? Five principles emerge, not as theory, but as operational necessity.

    Hunt Behaviours, Not Artifacts. A file hash changes. A domain rotates. An IP shifts. But the behaviour underneath, the credential abuse pattern, the lateral movement sequence, the exfiltration cadence, persists across campaigns and toolsets. Hunt behaviours and you detect threats you have never seen before. Hunt IOCs and you detect threats someone else already catalogued.

    Match the Machine's Clock Speed. If your threat hunting workflow is not automated, it is not threat hunting. It is a demonstration project. Automated baseline learning, real-time anomaly detection, instant cross-source correlation, and behavioural models that update without human intervention are the minimum viable response to the current threat velocity.

    Demand Context With Every Signal. An alert without context is noise with a timestamp. Every hunt finding must answer four questions: What happened? Is this normal for this user, this asset, this hour? What does threat intelligence say? What is the business impact? Speed without context is just fast noise.

    Map Your Blind Spots Or the Adversary Will. What percentage of MITRE ATT&CK techniques can your environment currently detect? If the answer is uncertain, that uncertainty is itself the vulnerability. You are hunting in selective darkness, leaving everything else unmonitored, which is precisely where a sophisticated adversary will operate.

    Make Every Hunt Compound. Every hunt should validate or invalidate a hypothesis, update behavioural baselines, feed the detection engineering pipeline, improve subsequent hunts, and expand measurable coverage. If a hunt does not make the organisation demonstrably stronger, it consumed resources without producing value.

    The Platform That Took This Seriously

    Spharaka Sphere™ was built on the premise that the entire threat hunting model requires reconstruction, not incremental improvement, but architectural reimagination for an era of AI-speed adversaries.

    Threat Intelligence at Operational Speed

    Consider the typical CVE response cycle. Day one: advisory published. Day two: an analyst reads the PDF. Day three: IOCs manually extracted. Day four: SIEM queries written. Days five through seven: investigation buried in false positives. Day eight, maybe an answer. Eight days. The vulnerability was exploited in the wild on day one.

    Spharaka Sphere™ collapses that timeline to minutes. Within 30 seconds, a CVE is auto-ingested, parsed, and enriched. Within two minutes, it is correlated against the entire customer environment. Within five minutes, behavioural hunt models are generated. Within ten minutes, findings are delivered to analysts contextualised, prioritised, and actionable.

    Natural Language Hunting

    The current state of threat hunting requires analysts to learn proprietary query languages, SPL, KQL, whatever dialect their SIEM speaks, map data sources manually, write complex cross-table joins, wait 20 minutes for execution, receive 10,000 unfiltered results, and then manually separate signal from noise. The bottleneck is not analytical skill. It is query infrastructure.

    An analyst types: "Show me PowerShell executions spawned from Office applications that made outbound connections to previously unseen external IPs in the last 24 hours." Results return in seconds, enriched with user and asset baselines, historical pattern analysis, threat intelligence correlation, MITRE technique mapping, and recommended next steps. The hunters hunt. They do not wrestle with syntax.

    Behavioural Analytics Without the PhD

    A traditional tool alerts: "Unknown process detected."

    Spharaka Sphere™ alerts: "Process chain is statistically anomalous for this user, accessing resources outside their defined role, at an unusual hour, matching MITRE T1078 (Valid Accounts), correlated with active threat intelligence on credential abuse campaigns." That is the difference between a fire alarm and a fire investigator.

    Visible Coverage

    Most SOCs hunt what they know how to hunt. Everything else is invisible, and adversaries live in the invisible. Spharaka Sphere™ provides real-time MITRE ATT&CK coverage mapping: green for techniques you can detect, yellow for partial coverage, red for blind spots. Then it generates hunt hypotheses specifically targeting your gaps.

    Compounding Returns

    Every hunt feeds a flywheel. A successful hunt automatically becomes a scheduled detection. A false positive updates the behavioural model. A newly discovered TTP enters the hunt library. A closed coverage gap updates the MITRE mapping in real time. Six months on the platform means six months of accumulated intelligence, refined models, eliminated blind spots, and automated detections, each iteration making the next sharper.

    The Numbers

    MetricBeforeAfterChange
    CVE response time7+ days< 1 hour99% reduction
    Hunt creation time2-4 hours3-5 minutes95% reduction
    False positive rate95%+< 15%80-point drop
    Coverage visibilityGuessworkReal-time MITREQuantified
    Time spent hunting~20%~75%3.75x increase

    The Maturity Question

    Where does your organisation sit?

    Level 0: Reactive. Wait for alerts. Investigate after damage. Hope. Roughly 30% of organisations. You are almost certainly already compromised and do not yet know it.

    Level 1: Basic Hunting. Manual, hypothesis-driven searches. IOC lookups. About 45% of organisations. You are hunting last month's threats.

    Level 2: Structured. Documented playbooks. Regular cadence. Some automation. Around 20%. You are systematically hunting yesterday's threats.

    Level 3: Continuous. Automated behavioural analysis. Integrated threat intelligence. Real-time coverage visibility. Approximately 4%. You are keeping pace.

    Level 4: Autonomous. AI-generated hypotheses. Machine-speed execution. Self-improving detection. Proactive prevention. Less than 1% of organisations. AI adversaries operate at Level 4.

    The Closing Window

    The average data breach now costs $4.45 million. But the deeper cost is institutional trust, and trust, once broken, does not recover on a quarterly earnings cycle.

    In 2019, defenders had roughly 60 days to find an intruder. By 2023, that window had narrowed to 16 days. For AI-powered attacks in 2026, the window is measured in hours. Every year, the adversary gets faster. Every year, the detection window shrinks. The tools, largely, stay the same. At some point, the arithmetic becomes unforgiving. The evidence suggests that point has arrived.

    The knife was fine when the other side had knives. They have drones now.

    About the Author

    Ravikumar Nalluri is the Co-founder and CTO of Spharaka Networks™. With nearly two decades of experience in cybersecurity, he is focused on redefining how organisations defend against AI-driven, automated attacks. Connect on LinkedIn.

    Hunt at Machine Speed

    See how Spharaka Sphere™ replaces query-driven hunting with autonomous, behaviour-led detection that compounds with every incident.

    Questions

    Frequently asked questions

    The questions this piece gets asked most often.

    Why are indicators of compromise no longer sufficient?

    Because an indicator describes infrastructure an adversary has already used and can cheaply discard. Matching one catches the attacks that were going to be caught anyway. It cannot express the case where legitimate tools are used in an illegitimate sequence, which is most competent intrusions.

    What is wrong with saying we have good threat intelligence?

    Usually that the intelligence is arriving rather than being used. Feeds are bought, deduplicated poorly, scored against nobody's actual estate, and consulted in a portal an analyst opens after they already suspect something. Intelligence that requires a context switch does not get used under load.

    Is behavioural detection too complex to operate?

    It is complex to build and it is not complex to operate, and those get conflated. What makes it feel unworkable is a baseline that cannot absorb a legitimate change, which produces a month of noise every time somebody moves team. That is a design problem rather than an argument against the approach.

    Will better analysts close the gap?

    No, and the belief that they will is the most expensive of the five fictions. The constraint is the number of investigations that can complete in a day, which is bounded by people rather than by their quality. Better analysts make each investigation better; they do not make the arithmetic work.