TL;DR: AI threat hunting works by automating evidence gathering, linking identity, cloud, endpoint, email, and SaaS signals, and guiding investigations with context-aware reasoning, according to Prophet Security. The key shift is that analysts keep the question, while the AI removes the swivel-chair work that used to make proactive hunting rare.
NHIMG editorial — based on content published by Prophet: AI Threat Hunting, How It Works
By the numbers:
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams use AI to speed up threat hunting without losing analyst judgment?
A: Use AI to gather evidence, link related entities, and suggest likely next questions, but keep the analyst in control of the final decision.
Q: Why do identity events matter so much in cross-domain threat hunting?
A: Identity events often provide the first reliable link between a user, device, cloud role, SaaS action, and service account.
Q: What breaks when cloud and identity logs are not correlated in one investigation flow?
A: Hunts become slow enough that analysts abandon them or miss the pivot point where an attacker moves from access to action.
Practitioner guidance
- Map hunt workflows to identity-first data sources Ensure your investigation stack can pull sign-in events, MFA prompts, OAuth grants, privileged role use, and service account activity into one timeline.
- Require evidence lineage for AI-assisted findings Make every AI-suggested investigative step traceable to source logs, queries, and timestamps.
- Prioritise service account and OAuth visibility in hunts Treat delegated access, token use, and service account activity as first-class hunt inputs, not background noise.
What's in the full article
Prophet's full article covers the operational detail this post intentionally leaves for the source:
- The specific user-driven hunt flow the vendor demonstrates, including how analysts move from one clue to a full investigation.
- The identity, cloud, endpoint, email, and SaaS data types the platform pulls together during a hunt.
- The explainability and query visibility details that show why a suggested investigative step was recommended.
- The practical examples of how analysts decide whether to open a case, enrich further, or dismiss a lead.
👉 Read Prophet's analysis of AI threat hunting and cross-domain investigations →
AI threat hunting and the governance gap in cross-domain investigations?
Explore further
Cross-domain hunt acceleration is becoming a governance issue, not just an analyst productivity issue. When investigators can move from one clue to a full timeline in minutes, the control question shifts from whether alerts exist to whether evidence is reachable and correlated fast enough to matter. That has direct implications for IAM and NHI programmes, because identity events are often the first reliable signal in a multi-stage intrusion. Practitioners should treat investigative latency as a measurable control outcome.
A question worth separating out:
Q: How do you know if AI-assisted hunting is actually improving security?
A: Look for shorter time to validated evidence, more repeatable hunt logic, and detections that are promoted from successful investigations. If the platform only creates faster reports, it is improving workflow, not security. Real improvement shows up when the team can confirm suspicious activity, preserve the chain of evidence, and rerun the same logic later.
👉 Read our full editorial: AI threat hunting is becoming cross-domain and analyst-led