- Home
- Capabilities
- Spharaka Autonomous Threat Hunting
Autonomous Threat Hunting Platform
Spharaka delivers continuous, AI-driven threat hunting across your entire environment. Hunt proactively at machine speed with MITRE ATT&CK-mapped hypotheses, behaviour-based hunting, and AI-generated hunt reports.
Continuous AI-Driven Threat Hunting
Stop waiting for alerts. Spharaka's Autonomous Threat Hunting agents continuously search your environment for adversary behaviour, novel TTPs, and dormant threats.
- Continuous AI-driven threat hunting across endpoint, identity, network, cloud
- Proactive threat detection before attacks escalate
- MITRE ATT&CK mapped hunting across tactics and techniques
- Behaviour-based hunting that catches living-off-the-land activity
- IOC and IOA hunting with multi-source threat intelligence
- Scheduled threat hunting campaigns aligned to your risk profile
AI-Generated Hunt Reports and Recommendations
Every hunt produces an analyst-ready report with evidence, scope, and recommended actions, automatically routed into AI SOAR for closed-loop response.
- AI-generated hunt reports with full evidence chains
- Hunt recommendations based on environment-specific risk
- Auto-promotion of validated hunts into detection rules
- Integration with AI SIEM and AI SOAR for autonomous response
- Customer-isolated AI memory for organisation-specific context
Hunting without an alert to start from
Threat hunting is normally a scarce senior analyst with a hypothesis and a spare afternoon. The scarcity is the problem: the estate changes faster than anyone can hunt across it.
Form a hypothesis
A hunt starts from a proposition about attacker behaviour, not from an indicator. "If an adversary had valid credentials here, what would the authentication pattern look like?" Hypotheses are generated from MITRE ATT&CK techniques, from threat intelligence about active campaigns, and from what this specific estate exposes.
Scope it to this environment
A generic hypothesis is untestable. It is narrowed against the actual estate: these domain controllers, these service accounts, this remote access path, these cloud roles. A hunt that cannot name what it is looking at will find nothing worth acting on.
Test against history
The hunt runs across retained telemetry rather than the live stream, because the point is to find what was already missed. This is where retention policy becomes a detection capability: a ninety-day window cannot answer a question about a dwell time longer than ninety days.
Separate finding from artefact
Most hypotheses return something, and most of it is legitimate. The step that makes hunting useful rather than exhausting is discriminating a genuine finding from the administrative habit that resembles it, which is where behavioural baselines do the work.
Report with evidence
Each hunt produces a written result: what was proposed, what was searched, what was found, what was excluded and why. A negative result is a real result, and recording it is what stops the same ground being covered repeatedly.
Promote what recurs
A hypothesis that finds something worth acting on becomes a standing detection, so the hunt does not have to be re-run to keep the coverage. This is how hunting compounds rather than resetting each cycle.
What a hunt draws on
Hunting is limited by retention and by breadth. A hunt can only ask questions the data can answer.
Where hunts run
- Retained endpoint process, file and registry history
- Authentication and directory records across the retention window
- Network flow, DNS and gateway history
- Cloud control plane audit history
- SaaS audit trails
- Industrial protocol history through Spharaka Signal
What hypotheses come from
- MITRE ATT&CK tactics and techniques, mapped to this estate
- Threat intelligence on campaigns active in your sector
- Behavioural baselines, for what would be abnormal here
- Asset and exposure data, for what is actually reachable
- Previous hunt results, including the negative ones
What a hunt produces
- A written hunt report with the evidence chain
- Findings promoted into cases for investigation
- New standing detections where a hypothesis proved out
- Coverage gaps, where the data could not answer the question
- A record of what was excluded and on what grounds
The most valuable output is often the coverage gap. A hunt that cannot be completed because a source is not retained has found a blind spot, which is worth more than most positive findings.
Continuous hunting against the scheduled kind
Almost every security team says it hunts. In practice hunting is what happens when a senior analyst has a quiet week, which is why coverage is uneven and undocumented.
| Aspect | Analyst-led hunting | Spharaka |
|---|---|---|
| How often it happens | When someone senior has time. In a busy quarter, not at all, and nobody notices because there is no output to miss. | Continuously, against a hypothesis backlog that does not depend on anyone's availability. |
| Coverage | Whatever the hunter happened to think of, shaped by their background and last incident. | Systematically mapped to ATT&CK tactics and techniques, so gaps in coverage are visible rather than assumed away. |
| Depth in time | Bounded by how much history a query can practically search before the analyst gives up waiting. | Bounded by retention, not by patience, which is what makes long dwell times findable at all. |
| Negative results | Rarely recorded, so the same ground gets covered repeatedly and nobody can say what has been checked. | Recorded with the same weight as positive ones, because knowing where you have looked is half the value. |
| Living-off-the-land activity | Findable, if the hunter thinks to ask about the specific tool and has time to sift the legitimate use. | The main case it is built for: legitimate tools used in illegitimate sequences, discriminated against baselines. |
| What happens to a finding | Written up, sometimes turned into a detection, often lost when the analyst moves on. | Promoted into a standing detection, so the coverage persists without the hunt being re-run. |
A hunt with no indicator to search for
The hypothesis: if an adversary had a foothold on a domain-joined host, they would enumerate the directory using tooling already present on the system.
Narrowed to built-in Windows tooling capable of directory enumeration, across all domain-joined hosts, over the full retention window. No hash, no domain, no IP, because the technique uses nothing that is not already installed.
Returns roughly eleven thousand executions. Almost all of it is legitimate: administrators, inventory scripts, software distribution, and a monitoring agent that does it hourly on every host.
Baselines separate the habitual from the exceptional. Which hosts do this routinely, which accounts, at what hours. Eleven thousand executions reduce to nineteen that do not fit any established pattern.
Of the nineteen, three occurred on hosts that also showed an unusual authentication within the preceding hour, from an account that does not administer them.
Two resolve to a contractor performing genuine work outside their normal hours, confirmed against the change record. One does not resolve, and becomes a case.
The discrimination logic that reduced eleven thousand to nineteen becomes a standing detection, so the next occurrence is caught live rather than at the next hunt.
The hunt found one thing worth investigating and produced a permanent detection as a by-product. Neither outcome was reachable by searching for an indicator, because the technique deliberately uses software the organisation installed itself.
What to ask a hunting platform
Hunting is the easiest capability to claim and the hardest to demonstrate, because a good hunt often finds nothing.
Show me a hunt that found nothing
Ask for the report. Whether a negative result is documented to the same standard as a positive one tells you whether hunting is a real process here or a search bar with a name on it.
How far back can it actually look?
Retention and query practicality are different limits. Ask how long a hunt across the full window takes, because a capability that is technically possible and takes eleven hours is not one anyone will use.
Which ATT&CK techniques are not covered?
A vendor who claims full coverage is describing a matrix, not a capability. The useful answer names the techniques the available telemetry cannot test for, which is also your data collection roadmap.
What happens to a finding afterwards?
Ask to see a detection that exists because a hunt produced it. If findings do not become standing detections, every hunt is starting from zero and the coverage never accumulates.
Frequently asked questions
What is Autonomous Threat Hunting?
Autonomous Threat Hunting is the use of agentic AI to continuously and proactively hunt for adversary behaviour across your environment, without depending on alerts or manual hypotheses.
How is AI Threat Hunting different from traditional threat hunting?
Traditional threat hunting depends on human-built hypotheses run on a periodic basis. AI Threat Hunting runs continuously, generates and validates hypotheses autonomously, and produces analyst-ready reports.
Is Spharaka's threat hunting mapped to MITRE ATT&CK?
Yes. Every hunt, detection, and report is mapped to MITRE ATT&CK tactics and techniques for unified coverage reporting.
Can validated hunts become detections?
Yes. Validated hunts can be promoted to AI SIEM detection rules automatically, continuously improving your AI SOC detection coverage.
Explore related capabilities
AI SOC Platform
Unified autonomous Security Operations Center.
Cyber Threat Intelligence
Multi-source CTI for hunt enrichment.
AI SIEM
AI log analytics and correlation.
AI SOAR
Autonomous response orchestration.
AI UEBA
Behavioural analytics for users and entities.
SAGE™ AI Model
Spharaka's proprietary Cybersecurity SLM that powers this capability.
Related use cases and guides
A hypothesis plane sweeping an estate of hosts, most clearing behind it, three unexplained and one promoted to a case.
Hunting for precursors before encryption begins.
Insider Threat
Hypothesis-driven hunts across identity behaviour.
Evaluating Autonomous Defence
How to test autonomous hunting in a proof of value.
See Spharaka Autonomous Threat Hunting in action
Discover how Spharaka's AI-native, autonomous cyber defence platform modernises your security operations.