Home/Services/Threat Hunting & Compromise Assessment
security service

Threat Hunting & Compromise Assessment

Suspect an intruder is already inside? Our threat hunting finds the attacker your alerts missed, with evidence and a clear verdict. Start now.

Manual, expert-ledEvidence-based findingsFree remediation retest

If you suspect an intruder is already inside your network right now, threat hunting is how you get a straight answer instead of a hunch. Our European team goes looking for the attacker your alerts never flagged: quiet persistence, credentials being reused, and the account that signs in at 3am from a country you have never sold to.

What threat hunting actually looks for

A vulnerability scanner tells you what could be exploited. Threat hunting answers the question that keeps you awake: is someone already here, and what have they touched? We start from an assumption of compromise and work backwards from evidence. That means hunting through logs, memory, and endpoints for the faint traces a patient attacker leaves, rather than waiting for a dashboard to turn red. In the compromises we clean up, the intruder had usually been resident for weeks before anyone noticed anything at all.

The hypotheses we hunt against

Good hunting is not random log-staring. We build specific, testable hypotheses drawn from real attacker behaviour and test each one against your telemetry. If a hypothesis holds, we pull the thread until we understand the full picture.

Active persistence: rogue scheduled tasks, systemd services, cron jobs, run keys and planted web shells
Credential abuse and lateral movement mapped to MITRE ATT&CK techniques and tactics
Beaconing to command-and-control infrastructure hidden inside normal-looking DNS and HTTPS traffic
Living-off-the-land activity: PowerShell, WMI, PsExec and legitimate admin tools bent to an attacker’s use
Suspicious mailbox rules, OAuth grants and token theft in Microsoft 365 and Google Workspace
Data staging and exfiltration: large archives appearing in odd places, then leaving your estate

Where the evidence lives

Attackers touch more than one place, so we correlate across sources instead of trusting a single feed. Endpoint process trees, authentication logs, EDR telemetry, firewall and proxy records, cloud audit trails, and volatile memory each hold a different fragment of the story. A login that looks fine in one log often looks alarming once you line it up against the process that spawned from it.

Proactive hunting versus a live compromise assessment

People arrive here for two different reasons, and the work differs accordingly.

Proactive threat hunting

Nothing has obviously gone wrong, but you want certainty before an audit, a funding round, or a board question you cannot answer with a shrug. Here the value is a documented, evidence-based verdict: either we find nothing and you can say so with confidence, or we surface something quietly that would otherwise have become a breach in a month.

Compromise assessment under suspicion

Something feels wrong. A supplier warned you, an antivirus alert fired and vanished, money moved, or a staff member reported strange behaviour. This is faster and more focused. We confirm or rule out an active intrusion, and if one exists we move straight into containment and full incident response without losing a day to handovers.

Managed and one-off engagements

Some clients want a single deep sweep. Others want recurring managed threat hunting so a fresh set of eyes examines their estate every quarter, tuned to the attacks that actually target their sector. We size the cyber threat hunting service to your risk, not to a fixed product tier.

Our response process

Whether you engage us proactively or mid-scare, the work follows the same disciplined path so nothing is skipped under pressure.

Triage

We start with a short call to understand your environment, what prompted the concern, and where your most valuable data sits. Within hours we are ingesting telemetry and forming the first hunting hypotheses. If there is an obvious active threat, triage compresses into minutes and we escalate at once.

Contain

If we confirm an intruder, containment comes before cleanup. We isolate affected hosts, cut attacker access, revoke stolen tokens and sessions, and reset the credentials in play, all while preserving evidence rather than trampling it. Rushing to wipe a machine destroys the very proof you need later.

Eradicate

We remove every persistence mechanism we have mapped, close the entry point, and verify the attacker cannot simply walk back in through a second door they left open. One backdoor is never the whole story, so we keep hunting until the estate is quiet.

Recover

We help you return clean systems to service in a sensible order, confirm that monitoring now sees what it previously missed, and watch for any sign the intruder tries to come back.

Harden

Finally we turn findings into fixes: detection rules for the techniques we saw, tighter logging where you were blind, and a short list of changes that would have stopped this. The point of a hunt is not just to find the attacker but to make the next one visible on day one.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

How they got in, and how we prove it

Every client asks the same first question: how did this happen? We treat that as core to the work, not an afterthought.

Root-cause forensics

We reconstruct the timeline from initial access through to the latest activity, so you can see the phishing email, the exposed service, or the reused password that opened the door. Understanding the root cause is the only way to be sure eradication actually holds.

Evidence handling

We work to a defensible standard. Findings are backed by hashes, timestamps and preserved artefacts, handled so they remain usable if the matter ever reaches insurers, regulators or a court. If you may need a formal forensic report, tell us at the start and we will collect accordingly.

What you get

You get a plain verdict first, then the depth behind it. No dashboard access we quietly bill for, no vague reassurance.

A clear compromised or not-compromised verdict, written for non-technical leadership
A technical report: every finding with evidence, affected assets, and MITRE ATT&CK mapping
A reconstructed attack timeline showing initial access, persistence and any data movement
Prioritised remediation steps your team can action immediately
Detection content and logging recommendations to close the blind spots we found
A debrief call to walk your team through the findings and answer questions
24/7
emergency hunts triaged around the clock
MITRE
every finding mapped to ATT&CK
Evidence
preserved to a defensible standard

Prevention after the hunt

A hunt that ends with a report and no change is a waste of your money. We close the loop.

Detection engineering

We write and tune the alerts that would have caught this attacker earlier, so the same technique lights up next time instead of slipping past. Where you lacked the logs to detect it at all, we tell you exactly which sources to turn on.

Reducing the attack surface

Most intrusions rely on something avoidable: an exposed remote-access service, a shared local admin password, or a mailbox with no multi-factor authentication. We give you the short list that matters most, ranked by how much risk each item removes. None of it is theoretical: every recommendation traces back to something we actually saw or could have seen in your own telemetry, so your team can prioritise with confidence instead of guessing.

Timelines and common triggers

Speed matters most when something is actively wrong, so here is what the clock usually looks like.

What to expect on the calendar

An emergency compromise assessment gets a same-day response and a first read on whether an intrusion is live, often within the first day of telemetry. A full estate hunt typically runs three to ten working days depending on how many endpoints and identities are in scope and how clean your logging is. We give you interim findings as we go rather than making you wait for a final document, because if we confirm an active attacker on day two you need to know on day two.

What usually brings people to a hunt

The triggers repeat. A bank or payment processor flags fraudulent transactions tied to your systems. An employee reports that colleagues received messages they never sent. A backup job suddenly balloons in size because data is being staged. A supplier tells you their network was breached and yours connects to it. Sometimes there is no single event, only a nagging sense that the last penetration test found too much and nobody ever checked whether it was already being abused. Any of these is a good reason to look properly rather than hope.

The cost of waiting

Dwell time works against you. The longer an intruder sits undetected, the more credentials they collect, the deeper their persistence goes, and the harder eradication becomes. Hunting early, while the footprint is small, is far cheaper than recovering from the full breach it would have grown into.

Pricing

Threat hunting is scoped by the size of your estate and how fast you need answers. A focused compromise assessment on a small environment is very different from an ongoing managed hunt across hundreds of endpoints, so we quote after a short call rather than pretend one number fits all.

Package What’s included Response time Price
Emergency compromise assessment Rapid confirmation of an active intrusion on a single environment, immediate triage and containment guidance On call, same day from €900
Hourly hunting Focused hunting and forensics led by a senior analyst, billed by the hour for smaller or well-defined scopes Starts within hours from €180/hr
Full compromise assessment Whole-estate hunt across endpoints, identity, cloud and network, with verdict and remediation plan 3–10 working days scoped after a call
Managed threat hunting Recurring hunts on a retainer, tuned to your sector, with agreed response SLA and discounted hourly rate Ongoing from €800/month
Large or complex estate Multiple sites, subsidiaries or a hybrid-cloud footprint, scoped to your needs On scoping custom

Every engagement is a fixed price agreed after a free scoping call, and a retest is included once you fix. Start emergency response

FAQ

How much does threat hunting cost?
A single emergency compromise assessment starts from €900, hourly hunting runs from €180/hr, and managed threat hunting on a retainer starts from €800/month. You get a fixed quote after a free scoping call, so there are no hourly surprises.
Can you tell me how they got in?
Yes. Root-cause analysis is central to every hunt. We reconstruct the timeline back to initial access, whether that was a phishing email, an exposed service or a reused password, so eradication actually closes the door.
What if you find nothing?
That is a valid and useful outcome. You get a documented, evidence-based verdict that your environment is clean, which is exactly what an auditor, insurer or board wants to see. We would rather confirm you are safe than invent a problem.
How is this different from my antivirus or EDR?
Those tools alert on known-bad patterns. A human hunter chases the quiet activity that never triggers an alert: legitimate tools used maliciously, stolen credentials in normal use, and slow, careful persistence designed to look ordinary.
Will hunting disrupt our operations?
No. Hunting is largely passive analysis of telemetry we collect. We only take disruptive action, such as isolating a host, once we have confirmed a threat and agreed the step with you.
Do you offer ongoing managed threat hunting?
Yes. Many clients move to a recurring managed threat hunting service after a first sweep, so a fresh analyst reviews their estate on a regular cadence and detection keeps improving over time.
Is the engagement confidential?
Completely. We work under NDA, and findings are handled securely and shared only with the people you name. Nothing about the engagement is disclosed anywhere without your instruction.
Can this support a compliance or audit requirement?
Yes. The report is written to support ISO 27001, SOC 2 and GDPR expectations around detection and incident readiness, and we can map findings to the framework you are working to.

Related services

Who needs this

Security and IT leaders who suspect a breach, teams preparing for an audit or acquisition, and organisations that want independent confirmation their environment is genuinely clean before something forces the question.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Threat Hunting & Compromise Assessment"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.