TL;DR: The number of detections shipped each month has tripled by combining human researchers with AI agents to sift trillions of browser events, surface novel attacks like InstallFix, and turn behavioral findings into production detections, according to Push Security. The key lesson is that speed and fidelity come from operationalised context, not bigger blocklists.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline”.
Key questions
Q: How should security teams detect browser attacks when domains and URLs rotate constantly?
A: They should move away from infrastructure-only blocklists and detect the technique instead.
Q: Why do human researchers still matter in agentic threat hunting?
A: Human researchers supply the context that makes agent output useful.
Q: What breaks when browser detections rely only on known-bad indicators?
A: The detections age out as soon as attackers rotate infrastructure or serve payloads only to active targets.
Practitioner guidance
- Prioritise behavioural browser signals Base detections on redirect chains, script behaviour, page structure, credential entry, and post-click actions instead of relying on domains, URLs, or IPs.
- Operationalise analyst context Turn your best hunters’ knowledge into a reusable TTP library, investigation notes, and validation prompts that agents can use repeatedly.
- Separate hypothesis, triage, and validation Use different agent roles for idea generation, false-positive reduction, and deeper investigation so one step does not contaminate the next.
Bottom line: Browser threat hunting is moving toward behavioural detection because infrastructure indicators are too easy to rotate and too weak to explain modern phishing tradecraft.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Behavioral hunting is now an identity control problem, not just a browser security problem. The article shows that the useful signal lives in consent prompts, redirected pages, credential entry, and post-click behavior. Those are identity events as much as they are web events, because the attacker is targeting the point where trust is granted. The practitioner takeaway is that browser telemetry belongs inside identity risk operations, not outside them.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
A question worth separating out:
Q: How can teams tell whether agent-assisted detection is actually working?
A: Look for detections that remain effective after infrastructure changes, plus a measurable drop in time from new technique discovery to production coverage. If the workflow only catches known bad domains, it is not really scaling threat hunting. It is just automating blocklists.
👉 Read our full editorial: Agentic threat hunting for browser attacks needs human context
Behavioral hunting is now an identity control problem, not just a browser security problem. The article shows that the useful signal lives in consent prompts, redirected pages, credential entry, and post-click behavior. Those are identity events as much as they are web events, because the attacker is targeting the point where trust is granted. The practitioner takeaway is that browser telemetry belongs inside identity risk operations, not outside them.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
A question worth separating out:
Q: How can teams tell whether agent-assisted detection is actually working?
A: Look for detections that remain effective after infrastructure changes, plus a measurable drop in time from new technique discovery to production coverage. If the workflow only catches known bad domains, it is not really scaling threat hunting. It is just automating blocklists.
👉 Read our full editorial: Agentic threat hunting for browser attacks needs human context
Behavioural hunting is replacing indicator chasing as the meaningful control boundary for browser attacks. Known-bad domains and URLs are too easy to rotate, which means they no longer describe the real security problem. The durable unit of analysis is the technique, not the infrastructure. Practitioners should treat browser telemetry as a behavioural evidence stream, not a blocklist input.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do teams know if AI threat hunting is actually improving detection?
A: Measure how quickly intelligence becomes an active hunt, how many hunts run continuously, and how often findings map to real adversary techniques rather than noise. If those metrics improve, the programme is becoming more operational. If they do not, the AI layer is only adding complexity.
👉 Read our full editorial: Agentic threat hunting for browser attacks needs human context