Threat hunting
Threat hunting starts from a guess about what an attacker might be doing and goes looking, rather than waiting for an alert.
The point is that alerts can only find what somebody already thought to write a rule for. Hunting looks for the things nobody wrote a rule for: a hypothesis, a look through the data, and a conclusion either way. A hunt that finds nothing is not a failure, because it has told you something about what is not happening, which is more than an empty alert queue tells you.
Checked against the primary source.
