Izerone Solutions Cybersecurity consulting

FLAGSHIP CONSULTING CAPABILITY

Threat hunting capability

Building the function, not just running the hunts. Methodology, playbooks, governance and mentoring, handed over to a team that keeps going without me.

Discuss an engagement

Why capability rather than delivery

A hunt run by an outsider who then leaves is worth something. A hunting function your own team runs afterwards is worth considerably more, and it is the work I am most often brought in for.

That means the unglamorous parts. Governance, so hunts happen on a schedule rather than when someone has a spare afternoon. Reusable playbooks, so a hunt does not depend on who is running it. Procedures and reporting that survive an audit. A feedback loop into detection engineering, so findings do not evaporate into a document nobody reopens.

I have taken a capability in a CNI environment from standing start to a governed function at Hunting Maturity Model Level 2, and led the team that runs it. If you are trying to do the same, Izerone can help shorten that path.

How a capability engagement runs

  1. Where you are nowAn honest read of your current maturity against the Hunting Maturity Model, based on what your team actually does rather than what the policy says.
  2. Telemetry and governance foundationsWhat you need to collect, and the cadence and ownership that make hunting a routine rather than an event. This often surfaces gaps worth fixing before any hunting begins.
  3. Methodology and playbooksIntelligence-led and hypothesis-driven hunts, mapped to MITRE ATT&CK, documented so your analysts can run them without me in the room.
  4. Mentoring the teamWorking alongside your analysts on live hunts, with review and quality assurance, until they are running them independently.
  5. Reporting and handoverExecutive and technical output covering findings, detection gaps and recommendations — plus the full playbook and query set, so the function is yours.

What a hunt is, for those weighing it up

A hunt starts with a question, not a tool. Something like: if an attacker had valid credentials in our environment, how would that look different from an administrator doing their job? That question becomes a hypothesis, the hypothesis becomes queries against your telemetry, and the queries produce either evidence or a documented negative result.

Both outcomes are worth having. A hunt that finds nothing still tells you something was not happening during that window, and still leaves you with a reusable playbook. Teaching a team to frame that question well is most of what capability building actually is.

Engagement shapes

Capability assessment

An honest read of where your hunting sits today against the Hunting Maturity Model — based on what your team actually does, not what the policy says. Delivered with a prioritised route to where you want to be.

Capability build

The main engagement. Methodology, reusable playbooks, operating procedures, governance and reporting — the structure that turns occasional searching into a function that runs to a schedule and survives people leaving.

Team development and mentoring

Working alongside your analysts on live hunts, with review and quality assurance, until they are running them independently and to a consistent standard. Capability lives in people, not documents.

Proof-of-concept hunt

A short, scoped hunt against agreed hypotheses. Useful where you need evidence that hunting will find something in your estate before committing to building the function.

Advisory retainer

Ongoing steer as the capability matures — reviewing hunt output, assuring quality, shaping the next stage. Advisory rather than delivery, sized to a few days a month.

Platforms

Hands-on across Microsoft Defender (KQL), IBM QRadar (AQL), Splunk and ArcSight, with exposure to XSIAM and Tenable. Endpoint, identity, authentication and network telemetry.

Capability work is largely platform-independent — methodology, governance and playbooks transfer. Where it matters is in mentoring your analysts on their own tooling, so if you run something I have not listed, say so at scoping and I will tell you plainly where my query fluency is deep and where it is not.

Common questions

We just want some hunts run. Is that in scope?

Yes, as a scoped proof-of-concept. It is often the right first step, and it gives you evidence about your own estate before committing to building a function. I will be straight with you about whether it is likely to be worth repeating.

How long does a capability build take?

Longer than a hunt and shorter than you fear. It depends on your starting maturity, how much telemetry work is needed first, and how much analyst time you can commit. Scope and duration are agreed in writing before anything starts.

Do we need to give you access to our environment?

For mentoring and playbook development, read-only access to the SIEM or EDR console is usually enough. Some clients prefer their analysts run the queries while I develop and interpret them — that works well, and is often the faster route through a security review.

What happens when the engagement ends?

You hold the methodology, the playbooks, the procedures and the query set, and your analysts have run them under review. That is the measure of whether the work succeeded. An advisory retainer is available afterwards, but it should be optional rather than necessary.

Will our name appear in your marketing?

No. Client names, sectors detailed enough to identify you, and environment specifics are never published or discussed. This work involves knowing where an organisation is weak, and that knowledge does not belong in a case study.

Can you work alongside our existing MSSP or SOC provider?

Yes, and it is often the most useful arrangement. Hunting capability sits with you rather than with the provider, which is usually where organisations want it once they think about who holds the knowledge.

Is this the same as a penetration test?

No. A penetration test asks whether someone could get in. Hunting asks whether someone already has, using your own telemetry to answer it.

Start with a conversation, not a proposal

Tell me what you are running and what is worrying you. If I am not the right fit I will say so, and point you at what is.

Get in touch