Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Threat hunting frameworks and AI automation: what SOCs need now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Threat hunting remains only partially automated in 48% of SOCs, even as teams rely on ATT&CK, Pyramid of Pain, and Cyber Kill Chain to structure investigations, according to SANS SOC Survey 2025. AI-augmented SOC platforms are shifting frameworks from manual methodology to repeatable execution, making analyst oversight more scalable than analyst-driven correlation.

NHIMG editorial — based on content published by Dropzone AI: Inside the SOC threat hunting frameworks and how AI teams automate them

By the numbers:

Questions worth separating out

Q: How should security teams implement threat hunting across identity, endpoint, and cloud data?

A: Build hunts around an attack hypothesis, then require the platform to correlate identity, endpoint, and cloud telemetry in one pass.

Q: Why do behaviour-based frameworks matter more than signatures in modern SOCs?

A: Because many modern intrusions are malware-free or rapidly changing, signatures and hashes age too quickly to support reliable hunting.

Q: What breaks when threat hunting stays partially automated?

A: What breaks is consistency.

Practitioner guidance

  • Standardise hunts around ATT&CK tactics Build hunt templates that begin with a tactic, then list the telemetry sources needed to confirm or exclude the technique across SIEM, EDR, and identity logs.
  • Prioritise TTP-level detections over disposable indicators Track which hunts still rely on hashes, IPs, or domains as primary signals, then rework them so durable behaviours drive escalation.
  • Include identity signals in hunt packs Correlate authentication anomalies, privileged session activity, and account-use patterns with endpoint and network telemetry when reconstructing attack paths.

What's in the full article

Dropzone AI's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step examples of how ATT&CK techniques are extracted from alerts and threat intelligence.
  • Illustrative workflow for correlating SIEM, EDR, and identity telemetry into one investigation.
  • Framework-by-framework examples showing how AI handles Pyramid of Pain prioritisation and Kill Chain timeline building.
  • Practical detail on how analysts review and validate the AI-generated hunt narrative.

👉 Read Dropzone AI's analysis of AI-augmented threat hunting frameworks →

Threat hunting frameworks and AI automation: what SOCs need now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Framework automation is now a SOC capacity issue, not a methodology issue. The article is right to frame ATT&CK, the Pyramid of Pain, and the Cyber Kill Chain as proven methods, but the limiting factor is execution at scale. When 24/7 teams have mixed experience levels, the quality gap sits in repetitive correlation work, not in the framework itself. The practical conclusion is that SOC maturity increasingly depends on whether teams can industrialise framework application without losing analyst judgment.

A question worth separating out:

Q: What should SOC leaders do when identity signals are missing from hunt workflows?

A: SOC leaders should treat that as a visibility gap, not a tooling nuisance. If hunts do not include authentication, privilege, and session data, attackers can move through credentials and access paths without being placed into the full attack timeline. Identity telemetry belongs in the same operational workflow as endpoint and cloud data.

👉 Read our full editorial: AI-augmented threat hunting frameworks are changing SOC operations



   
ReplyQuote
Share: