A Hunch Isn't
A Hypothesis.
A structured method for hypothesis-driven threat hunting: where a real hypothesis comes from, how to scope and document a hunt before starting it, and the habits that quietly turn a hunt into confirmation-seeking. This methodology leans on the models covered in Attack Lifecycle & Adversary Models, especially the Pyramid of Pain's push from IOC-matching up to TTP-hunting. Track and manage hypotheses with HYPOS.
Hypothesis Anatomy
Six parts, in order. Skip one and the hunt either can't start cleanly or can't end conclusively.
The Six Parts, In Order
1. Observation / Trigger What prompted this hunt ├── A threat intel report describing a new or updated TTP ├── A Pyramid-of-Pain move from IOC-hunting up to TTP-hunting └── An ATT&CK coverage gap surfaced during a detection review // no trigger on record means no reason this hunt is running today instead of last month 2. Hypothesis Statement A specific, falsifiable claim ├── Bad: "look for bad stuff" — nothing here can be confirmed or refuted └── Good: "an attacker is using WMI for lateral movement in the finance VLAN" // if a statement can't be wrong, it was never a hypothesis 3. Data Sources Needed Named explicitly, before the hunt starts ├── Log source, retention window, and field coverage, all confirmed to exist └── Discovering mid-hunt that the log source doesn't exist wastes the trigger that started the hunt // scoping the data is analysis, not paperwork to skip 4. Analysis Method The query or technique that actually tests the statement ├── A specific search, a stacking method, a baseline comparison, or a pivot sequence └── Should map directly to the hypothesis statement, not to whichever query is easiest to run // the method has to test the claim, not just search somewhere near it 5. Expected Evidence If True What a confirmed hypothesis actually looks like in the data, written down before looking // stated in advance, so a real hit doesn't get rationalized after the fact 6. Expected Evidence If False The negative outcome, defined in advance └── Without this, the hunt can't conclude anything, true or false // a hunt that can't fail was never testing a hypothesis in the first place
Where Hypotheses Come From
A hunt doesn't start from a blank page. It starts from one of a small set of real triggers.
Threat Intelligence
Pyramid Of Pain Progression
ATT&CK Coverage Gap Analysis
Findings From Another Investigation
Structuring The Hunt
The difference between a hunt that concludes and one that just quietly stops.
Scope Before You Start
Define The Null Result
Document As You Go
A Negative Result Is Still A Result
Common Pitfalls
Mistakes that don't show up in the hunt itself. They show up in what the hunt failed to tell anyone.
Confirmation Bias
Hunting Without A Documented Hypothesis
No Baseline To Compare Against
Treating A Completed Hunt As Permanent
Full Example
Every part from Hypothesis Anatomy above, filled in for one real hunt.
WMI Lateral Movement Hunt
Observation: Threat intel reports a campaign using WMI (Win32_Process Create) for lateral movement. Hypothesis: This technique is present in our environment within the last 30 days. Data sources: ├── Sysmon Event ID 1 (process creation), filtered for wmiprvse.exe as parent └── Windows Security Event ID 4688 Analysis method: Query for wmiprvse.exe spawning an unexpected child process across all hosts in the 30-day window. Expected evidence if true: wmiprvse.exe as parent of cmd.exe or powershell.exe, on hosts with no legitimate WMI-based admin tooling. Expected evidence if false: Zero matches, or all matches trace to known, documented WMI-based management tools (e.g. an RMM agent). // WMI-based lateral movement maps to ATT&CK T1047 (Windows Management Instrumentation). // Citing the technique ID here does the same job meta.reference does for a YARA rule: // it gives whoever inherits this hunt next a fixed point to start from.