How Mature Is the Program, Actually.
And How Do You Measure It.
Sliding Scale of Cyber Security shows where investment goes as a program matures. SOC Visibility Triad shows what data actually backs it. PEAK and the Hunting Maturity Model grade the hunt practice itself — from ad-hoc alerting to a program that turns its own findings into standing detections.
01
ARCHITECTURE
Secure design: segmentation, hardening
›
02
PASSIVE DEFENSE
Defends without a human: IDS/IPS, firewalls
›
03
ACTIVE DEFENSE
Analyst-driven monitoring, threat hunting
›
04
INTELLIGENCE
Collect and analyze adversary data to decide
›
05
OFFENSE
Legal countermeasures — nation-state/LE only
INCREASING COST, SKILL, AND LEGAL AUTHORITY REQUIRED →
NETWORK
NDR
Network Detection & Response
Sees traffic an endpoint agent can't: unmanaged devices, IoT, encrypted-metadata patterns, east-west lateral movement between hosts with no agent on either end.
ENDPOINT
EDR
Endpoint Detection & Response
Sees what the wire can't: process trees, command lines, in-memory injection, and file activity — the ground truth for what actually executed.
CENTRAL
SIEM / Log Management
Correlates the other two, plus everything else
The only point that sees identity, cloud, application, and auth logs alongside NDR and EDR telemetry — where cross-source correlation and long-term retention actually happen.
01
PREPARE
Pick a topic, research it, scope the hunt
›
02
EXECUTE
Dig into the data, test the hypothesis
›
03
ACT WITH KNOWLEDGE
Document, automate the finding, communicate it
0
INITIAL
Mostly automated alerting, little to no hunting
›
1
MINIMAL
Follows external threat intel, procedural at best
›
2
PROCEDURAL
Runs published hunting procedures from others
›
3
INNOVATIVE
Builds its own hunting procedures, strong data access
›
4
LEADING
Automates successful hunts into standing detections
HM0 → HM4 — MOST ORGS TOP OUT AROUND HM2 WITHOUT DEDICATED HUNT HEADCOUNT
RELATED
TaHiTI
Targeted Hunting integrating Threat Intelligence
A hunting-process framework from a Dutch financial-sector consortium, built on top of the Hunting Maturity Model above. Adds a third hunt trigger — the unstructured / data-driven hunt — alongside intel-driven and situational-awareness hunts, plus formal hunt-abstract and evaluation documentation.