Automate to amplify your hunters, but be careful not to over-automate analyst reasoning.
Is your team running each new threat report through AI to generate a hunt? They’ll get a reasonable hunt in seconds, but one only scoped to that threat report. The AI will also likely give a different answer on the second attempt. Left unchecked, this practice can create a wide gap in coverage the program doesn’t take into account.
The SANS 2026 Threat Hunting Survey found that usage of formally defined threat hunting methodologies fell for a second straight year, to 37%, down from 46% in 2025 and 51% in 2024. A formally defined methodology generally means a documented, repeatable process covering how hunts are triggered and scoped, how hypotheses are written and how findings are handed off. Meanwhile, ad hoc approaches to hunting crept up to 39%, slightly outpacing formal methodologies. In ad hoc hunting, there is no written structure that everyone follows, no consistent hypothesis format, and no standard way to validate that the data needed for the hunt is being logged.
SANS points to staffing as the likely main driver of this trend, with 38% saying available headcount drives which methodology gets used, while another 39% say it’s a combination of staffing and methodology. Skills shortages are the top barrier for 45% of programs. The result, as SANS put it, is methodology bends to what people can handle rather than what’s most effective. While skilled hunters can thrive in ad hoc hunting, the program may suffer due to results that are hard to reproduce and measure.
Source: SANS 2026 Threat Hunting Survey
Another possible driver of ad hoc hunting is AI. “One thing we’re watching is whether AI is unintentionally making ad hoc hunting easier to sustain,” says Scott Poley, Senior Threat Hunt Manager at Intel 471. In talks and training sessions, he’s increasingly hearing the default response to a new threat report is to run it through AI. “AI gives them a reasonable hunt for what’s described in the report, but people skip the extra steps taken with a proper methodology. When AI lets you answer things faster, structured approaches can fall away.” These processes are designed by experienced hunters to make hunts reusable and drive program maturity.
A proper methodology adds four steps: narrowing the report to a specific behavior, researching and reproducing it, validating that the hunt detects it, and enriching it with what’s known about the actor. All of this depends on behavioral evidence. A report about a malicious insider stealing account information gives a hunt a direction, but there are too many ways to achieve that goal to validate against. Knowing the actor used PowerShell to enumerate Active Directory accounts narrows it to a short list of commands. With the actual commands or tooling hashes, hunters can reproduce the behavior in a lab and build a hunt proven to find it.
With a validated hunt, you know it will identify the behavior if it’s present in logs, and you can explain why when it finds nothing. That’s the work of making a hunt reliable and repeatable. “The craft is understanding the behavior behind the activity,” says Poley.
This structured approach is more important today as adversaries default to techniques that evade traditional, indicator-based detection. Living-off-the-land techniques topped every threat actor category hunters uncovered, according to the SANS 2026 data: 72.7% for nation-states, 63.4% for ransomware groups and 63.2% for organized crime. Signature-matching won’t find threats that abuse legitimate admin tools and valid credentials. Well-scoped behavioral hunts can.
“Our job isn’t just to address the actor or the specific nuance in the report we’re working from,” adds Poley. “It’s thinking about the permutations of that attack — how it could be changed slightly and still achieve the same thing.”
None of this means AI can’t be used. Poley’s advice is to treat AI as a teammate that reinforces your methodology. “When you want to explore an idea, use it to question your logic or your hypothesis.”
TaHiTI 2.0: data, data quality, and what not to over-automate
SANS suggests that organizations without a defined hunt methodology explore frameworks such as TaHiTI (Targeted Hunting integrating Threat Intelligence). TaHiTI is a methodology for structured, hypothesis-based hunting that treats threat intelligence as the starting point for a hunt and to contextualize and enrich hunts during an investigation. The Dutch Banking Association (NVB) published TaHiTI version 2.0 in October 2026. Developed by members of the Dutch Financial Institutions Information Sharing & Analysis Centre (FI-ISAC). TaHiTI 2.0 outlines key hunt processes, metrics for hunts and program maturity, and best practices for governance, log retention, reuse of previous hunts and automation. Notably, it warns to “avoid over-automating hypothesis generation and analyst reasoning.”
The reason to avoid over-automation in these specific aspects of hunting comes back to the hunter understanding behaviors and knowing where automation does and doesn’t drive program maturity.
A hunt built around the underlying behavior finds any actor observed using it, not just one actor. When Intel 471’s hunt team reviews a new report, they first check their hunt library on Verity471 for what’s already covered, what needs updating and whether a net-new hunt is needed. According to Poley, 80 to 90% of the behaviors seen in reports are already covered generically by existing hunts.
Below, we look at what a structured, intelligence-driven approach involves and why it matters. Then, we show how Hunt on the Verity471 cyber intelligence platform supports each of TaHiTI’s three phases: Initiate, Hunt and Finalize.
Hunters don’t want shackles, but discipline pays dividends
An obvious objection to formalizing a methodology is sacrificing a hunter’s autonomy and creativity. Poley agrees that’s a risk. “You don’t want a methodology so bureaucratic that you can’t do the work. It shouldn’t be handcuffs; it should enable you.”
Building a methodology that the team actually sticks to also takes effort. “A good methodology takes a lot of work up front,” he says, “but if you’re doing it for the right reasons, you earn a lot of time back because your approach is so effective.”
The scarcity of skilled hunters makes it hard for a program to conduct the research, testing and validation involved in creating hunt content. That can take several days of work even before executing the hunt and documenting findings before hand off. Having a formally defined methodology doesn’t guarantee it gets used. SANS respondents described documented processes that aren’t strictly followed and hypothesis-based approaches that only some analysts are comfortable executing. This suggests teams that formalize a threat hunt methodology can benefit from tools that reinforce standard operating procedure.
Measuring maturity, not just activity
Measurement is sliding too. Seventy percent of respondents report that threat hunting has improved their organization’s overall security posture in the past 12 months. But only 40% of organizations formally measured the success of their threat hunting this year, down from 64% in 2024. As the SANS report notes, it’s hard to demonstrate value to leadership or justify headcount without a structured way to assess outcomes.

Source: SANS 2026 Threat Hunting Survey
Nearly half of survey respondents run three to ten hunts a month, and 31% say a typical hunt takes nine to 24 hours. While hunt counts show a team is busy, Poley argues the stronger measure is how well a program addresses risk to the organization. Intel 471’s hunt team tracks four measures for its own library:
- Pre-existing coverage: Did we already have a hunt for this behavior, and how long before public disclosure did we have it?
- Reuse rate: How often does a hunt apply to new actors, campaigns and incidents as they emerge?
- Gap closure time: How quickly can we address a new behavior when it appears?
- Enhancement rate: How often do we improve a good hunt with something new, rather than starting from scratch?
“Those measurements show the maturity of a hunting program and the value of addressing risk rather than a single threat,” says Poley. They also align with TaHiTI, which treats a hunt’s output not only as a threat found, but as the lessons and insight that make future hunts more efficient and mature the program itself.
How Hunt on Verity471 amplifies TaHiTI programs
TaHiTI sets out how to perform structured hunts. HUNTER on Verity471 enables much of what it takes to use this methodology, but leverages Intel 471’s own methodology and processes to make every hunt package as actionable as possible. Here’s how that maps to TaHiTI’s three phases to amplify threat hunter effectiveness and mature the hunt program with consistent hunt management processes.
Initiate: Your hunt team decides
TaHiTI’s Initiate phase standardizes what triggers a hunt (intelligence, reporting, incident response or other investigations) and what’s in scope. Only the customer’s program can define that.
HUNTER on Verity471 assists prioritization with Emerging Threats Collections that contain relevant hunt packages within 24 to 72 hours of a major threat breaking. Contextual tagging (MITRE technique and tactic, threat names, industry, severity, motivations and CVEs) lets teams pivot from intelligence reports with behavioral detail on Verity471’s Intelligence mode to relevant hunts. Teams prioritize hunts against their own intelligence requirements and risk profile.
Hunt phase: HUNTER packages do the heavy lifting
This is where the HUNTER Hunt module on Verity471 does the heavy lifting for teams building a defined methodology around TaHiTI. Because Intel 471’s methodology is built into each hunt package, it reduces the burden on analysts applying it consistently. Everything a hunter needs to capture is already in the package: the hypothesis and CTI context, runbook, analyst notes, deployment steps, mitigation recommendations, log source categories (such as EDR, Windows event logs and Sysmon) and Emulation and Validation packages. The library covers more than 220 adversaries and 800 behaviors that attackers adopt to evade detection. Every package is validated, and it’s only linked to a threat actor or malware family when the behavior has been directly observed in that actor’s activity or the link is assessed with high confidence.
Take The Gentlemen, one of today’s most prolific ransomware groups. One of 20 packages in our Gentlemen Hunt Collection, “RDP Restricted Admin Mode Enabled — Registry Key Detection” (login required), detects the DisableRestrictedAdmin registry key being set to 0. That lets an attacker move laterally over RDP with stolen password hashes, a pass-the-hash technique commonly used before encryption.
The package was built in 2025, when Gootloader was observed using the technique. Since then, The Gentlemen, Qilin, Akira and several other ransomware operators have used it too. If the hunt finds nothing, the Emulation and Validation package can be used to confirm whether that’s a true negative or a visibility gap. Hunts are critical for driving new detections and mitigations that should be recorded to demonstrate the value of the hunt program.
Finalize: Assisted evidence capture, handoff and reporting
TaHiTI’s final phase hands results to incident response, detection engineering, security monitoring and threat intelligence. Each organization’s hunt program defines its own outputs. However, the Hunt Management Module (HMM) helps teams capture, annotate, modify, update and track hunt use cases in one place. HMM automatically captures the evidence and records findings and status against each package such as new detections created from a hunt. When a hunt closes, the HMM pre-populates a report with the intelligence context, query logic, findings, evidence, scope and remediation, in technical and executive versions. Coverage metrics are captured automatically, and empty results that expose visibility gaps become evidence-backed logging recommendations.

The Hunt Management Module: Track Intel 471 hunts and your custom hunts against threats and MITRE techniques.
A faster path to structured hunting
The SANS data suggests many programs are drifting away from structured hunting due to staffing challenges that undermine standard operating procedures. TaHiTI provides the structure that keeps hunting repeatable, defensible and easy to hand to the next analyst. The Hunt Module on Verity471 is built to make that structured path faster, with AI that works around the hunt rather than creating the hunt. MCP471 connects existing AI tools to Verity471 intelligence. Agent471 on Verity471 is a virtual member of the team with Intel 471 analyst tradecraft built in that delivers cited adversary intelligence and helps analysts reach the right behavioral hunts faster. Read the full SANS 2026 Threat Hunting Survey.
HUNTER Community is the right place to start or accelerate a structured, intelligence-driven threat hunting program. Get a 30-day, no-fee trial with access to dozens of hunt packages built by Intel 471’s threat hunters, complete with emulation and validation, so you can see how a methodology built into every hunt works in your own environment.
Sign up for HUNTER Community →

